E18-3gub1
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
t
Variants:
10
Year:
2018
Description
This strike exploits a policy bypass vulnerability in Apache httpd FilesMatch. FilesMatch is intended to prevent files which do not match certain regex patterns to be uploaded via HTTP PUT messages. One of these patterns is AP REG DOLLAR ENDONLY, which is intended to prevent files ending with the \n character. However, this option does not work properly, allowing for files ending with \n to be uploaded. An attacker can send a specially crafted HTTP PUT message to bypass the policy and upload arbitrary files.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}