CVE-2018-16384: SQL Injection
Published Sep 3, 2018
·Updated
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {ab} where a is a special function name (such as "if") and b is the SQL statement to be executed.
Affected Software
3 affected components
owasp OWASP ModSecurity Core Rule Set<=3.0.2
owasp OWASP ModSecurity Core Rule Set=3.1.0-rc1
owasp OWASP ModSecurity Core Rule Set=3.1.0-rc3
Event History
Sep 3, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-16384?
CVE-2018-16384 is a vulnerability that allows for a SQL injection bypass in the OWASP ModSecurity Core Rule Set.
2
How does CVE-2018-16384 work?
CVE-2018-16384 works by exploiting a SQL injection vulnerability in the OWASP ModSecurity Core Rule Set.
3
What is the severity of CVE-2018-16384?
The severity of CVE-2018-16384 is high with a CVSS score of 7.5.
4
Which software versions are affected by CVE-2018-16384?
The OWASP ModSecurity Core Rule Set versions 3.0.2, 3.1.0-rc1, and 3.1.0-rc3 are affected by CVE-2018-16384.
5
How can I fix CVE-2018-16384?
To fix CVE-2018-16384, it is recommended to update to a patched version of the OWASP ModSecurity Core Rule Set.