PoC:
We can see that PHProxy has filtered some intranet addresses.
However, it can still be bypassed by resolving the domain name to an intranet address.
A simple proof is shown below.
vul.aegisrisk.xyz is bound to 127.0.0.1
If the proxy accesses http://vul.aegisrisk.xyz:8080/info, it will access port 8080 of the intranet address.
Received the request: