CVE-2017-15715 is an access-control bypass in Apache HTTP Server 2.4.0 through 2.4.29 involving regular expressions configured through the FilesMatch directive. Before the fix, the regular-expression engine could allow the $ anchor to match before an embedded newline in a filename rather than exclusively at the end of the complete filename. A filename with a trailing newline can therefore satisfy a FilesMatch rule intended to match a prohibited filename suffix while retaining additional content after the newline.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
$ anchor to enforce upload or execution restrictions. Reject, normalize, or safely encode filenames containing newline characters before they reach Apache HTTP Server, and enforce file-type validation and execution controls outside filename-based matching where possible.Patch, then assume compromise.
$ matches only the end of the input string by default rather than embedded newline positions. Apply vendor-supported backported packages where applicable; for Red Hat Enterprise Linux 7, the affected advisory provides an updated httpd package version 2.4.6-95.el7.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Dockerized proof-of-concept environment for CVE-2017-15715, an Apache HTTP Server parsing issue that can allow FilesMatch/extension-based upload protections to be bypassed when a filename ends with a newline after .php. The repo contains four files: a Dockerfile that builds a vulnerable Apache/PHP container from vulhub/php:5.5-apache, a docker-compose.yml that exposes the service, a README describing reproduction steps, and index.php, the vulnerable upload application. The core exploit logic is in index.php. It accepts a file upload plus a separate attacker-controlled filename from POST parameter name. It extracts the extension using PHP pathinfo() and blocks common PHP extensions (php, php3, php4, php5, phtml, pht). However, because the filename is user-controlled and only basename() is applied, a filename such as 1.php followed by a newline can evade the extension check while still being interpreted by vulnerable Apache/mod_php when requested as /1.php%0a. The script then writes the uploaded file directly into the web-accessible current directory using move_uploaded_file(), making the uploaded payload reachable and executable. This is a real exploit lab rather than a scanner or framework module. It does not include an automated exploit client; instead it provides a vulnerable target and demonstrates the exploitation workflow manually, likely using a proxy such as Burp Suite to inject the newline byte into the filename. The capability provided is upload-filter bypass leading to execution of arbitrary PHP code on the server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Apache HTTP Server access-control bypass in which a filename ending in a trailing newline can bypass <FilesMatch> restrictions.
Low-severity file-upload restriction bypass involving newline handling in FilesMatch expressions.
A regular expression handling vulnerability in Apache HTTP Server core related to '$' matching embedded newline characters.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.