Описание
VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args or get_post_args) to block the API misuse described in CVE-2018-9230.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:verynginx_project:verynginx:0.3.3:*:*:*:*:nginx:*:*
EPSS
Процентиль: 65%
0.00481
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-755
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args or get_post_args) to block the API misuse described in CVE-2018-9230.
EPSS
Процентиль: 65%
0.00481
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-755