Skip to content

Vhost request for apps might expose locally running servers or other website data #7

@csoni111

Description

@csoni111

Currently one can access any local server running on the hda machine using Vhost/? in User-Agent header, for example Vhost/localhost:3000/blah-blah or even more vulnerable could be Vhost/anywebsite.com.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions