摘要:
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
安全等级: Low
公告ID: KylinSec-SA-2022-2521
发布日期: 2022年10月24日
关联CVE: CVE-2020-22669
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2020-22669 | KY3.4-4A | mod_security_crs | Unaffected |
CVE-2020-22669 | KY3.4-5A | mod_security_crs | Unaffected |
CVE-2020-22669 | KY3.5.1 | mod_security_crs | Unaffected |