CVE-2018-19991

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2018
Last modified:
24/08/2020

Description

VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args or get_post_args) to block the API misuse described in CVE-2018-9230.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:verynginx_project:verynginx:0.3.3:*:*:*:*:nginx:*:*


References to Advisories, Solutions, and Tools