chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
378 stars 24 forks source link

Add rule for CVE-2024-4577 #266

Closed egibs closed 3 weeks ago

egibs commented 3 weeks ago

This PR is an attempt to detect the conditions for CVE-2024-4577 --

This will match the specific POC request which matches this from the pentesterlab post for CVE-2012-1823: CleanShot 2024-06-10 at 14 38 34@2x

allow_url_include and auto_prepend_file were covered in the Dodgy PHP rules (separately), but I didn't see a soft-hyphen rule unless searching failed me.