← All CVEs

CVE-2017-15715

high · 8.1

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

8.1
CVSS
85.5%
EPSS (exploit prob.)
100th
EPSS percentile
2018-03-26
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, <= 2.4.29
debiandebian_linux8.0
debiandebian_linux9.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux17.10
canonicalubuntu_linux18.04
netappsantricity_cloud_connectorall versions
netappstorage_automation_storeall versions
netappstoragegridall versions
netappclustered_data_ontapall versions
redhatenterprise_linux6.0
redhatenterprise_linux7.0
redhatenterprise_linux7.4
redhatenterprise_linux7.5
redhatenterprise_linux7.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-15715