The attacker crafts a request to the target server.
Unauthenticated Remote Code Execution (RCE). 53387.rar
The flaw stems from via improper handling of the X-Forwarded-For header in HTTP GET requests. The attacker crafts a request to the target server