cve/2023/CVE-2023-30802.md
2024-06-18 02:51:15 +02:00

18 lines
842 B
Markdown

### [CVE-2023-30802](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-30802)
![](https://img.shields.io/static/v1?label=Product&message=Net-Gen%20Application%20Firewall&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%208.0.17%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-540%3A%20Inclusion%20of%20Sensitive%20Information%20in%20Source%20Code&color=brighgreen)
### Description
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.
### POC
#### Reference
- https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4
#### Github
No PoCs found on GitHub currently.