Security Research

CVE-2024-38475 Apache HTTPD mod_rewrite path traversal: from BlackHat 2024 to RCE

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of Apache mod_rewrite path traversal and conference stage

A path-matching logic flaw in Apache HTTPD mod_rewrite, CVSS 9.1, disclosed at BlackHat 2024. An attacker crafts a special URL to bypass rewrite rules and access restricted files.

Unlock to view this content.