安全研究

CVE-2024-38475 Apache HTTPD mod_rewrite 路径穿越:从 BlackHat 2024 到 RCE

#漏洞分析#代码审计#Web安全
深色背景下的 Apache mod_rewrite 路径穿越与会议舞台

Apache HTTPD mod_rewrite 的路径匹配逻辑缺陷,CVSS 9.1,BlackHat 2024 上披露,攻击者构造特殊 URL 绕过 rewrite 规则访问受限文件。

Unlock to view this content.