
Rapport de bug bounty professionnel détaillant l'exploitation d'une vulnérabilité Blind SSRF menant à une exécution de code à distance Shellshock (CVE-2014-6271), confirmée via un callback DNS out-of-band.
Ce dépôt contient un rapport professionnel de bug bounty démontrant l'exploitation réussie d'une vulnérabilité de SSRF aveugle ayant atteint un point de terminaison CGI interne vulnérable à Shellshock (CVE-2014-6271). L'exécution de commandes à distance a été confirmée à l'aide d'un rappel DNS hors bande (OAST), mettant en évidence la chaîne d'attaque complète, analyse technique.