Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c43r-649m-6vgp

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.

EPSS

Процентиль: 62%
0.00436
Низкий

Связанные уязвимости

nvd
больше 16 лет назад

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.

EPSS

Процентиль: 62%
0.00436
Низкий