In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty
We have discovered 73,544 live websites that are affected by CVE-2018-9230.
Product | ![]() |
Category | Web Servers |
Vulnerable Domains | 73,544 live websites (16.61% of OpenResty install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 19 versions ( 41.30% of all versions) |
![]() | 1,702 websites |
![]() | 70,161 websites |
![]() | 649 websites |
![]() | 397 websites |
![]() | 232 websites |
![]() | 82 websites |
![]() | 69 websites |
![]() | 64 websites |
![]() | 30 websites |
.com | 53,236 websites |
.org | 5,267 websites |
.net | 4,098 websites |
.info | 1,607 websites |
.de | 909 websites |
.co.uk | 775 websites |
.co | 552 websites |
.io | 470 websites |
.it | 313 websites |
.jp | 203 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.**.uk | ![]() | *,*** | |
*************.**.com | ![]() | **,*** | |
***.com | ![]() | **,*** | |
***********.**.uk | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
********.studio | ![]() | **,*** | |
****.media | ![]() | **,*** | |
**************.**.uk | ![]() | **,*** | |
*************.org | ![]() | **,*** | |
*******.**.uk | ![]() | **,*** |