PoC Index

CVE-2017-15715

HIGH 8.1EPSS 85.7%

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

CVSS v3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
85.72% chance of exploitation in the next 30 days, 100th percentile
Nuclei
high · CWE-20
Published
2018-03-26
Updated
2024-09-17

Proof-of-concept exploits (1)

Nuclei templates (1)

Vulhub environments (1)

Exploit collections (1)

References

Related