Jump to content

Recommended Posts

[client 216.80.102.45] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:(?:advertiser|campaign|affiliate|zone|channel)\\\\-edit|account\\\\-user\\\\-(?:name\\\\-language|email|password))\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/modsecurity.d/rules/comodo_free/30_Apps_OtherApps.conf"] [line "6000"] [id "240530"] [rev "3"] [msg "COMODO WAF: CSRF protection bypass in Revive Adserver before 3.2.2 (CVE-2015-7364)||adserver.440music.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"I can't tell you how many times I've updated Revive and I've never been able to get it to update. Again today I had to do a fresh install and the database won't update using phpmyadmin or command line. Now that I've updated the script and the database won't update I have to add all the banners and users from scratch.
Here is the issue today.

Adding a New User when I click on "Save Changes" I get a 403 error
www/admin/advertiser-edit.php
the file is there and permissions are set to 644 I also tested at 755 same results.
error log:

[client xxx.xxx.xxx.xxx] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:(?:advertiser|campaign|affiliate|zone|channel)\\\\-edit|account\\\\-user\\\\-(?:name\\\\-language|email|password))\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/modsecurity.d/rules/comodo_free/30_Apps_OtherApps.conf"] [line "6000"] [id "240530"] [rev "3"] [msg "COMODO WAF: CSRF protection bypass in Revive Adserver before 3.2.2 (CVE-2015-7364)||adserver.440music.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "adserver.440music.com"] [uri "/www/admin/advertiser-edit.php"] [unique_id "YmG2j1TymD1NA5ZnUCNTAQAAAAM"], referer: https://adserver.440music.com/www/admin/advertiser-edit.php

 

Link to comment
Share on other sites



×
×
  • Create New...