
11/13/2017 · Alex Cruz Farmer
What this post added
This post details specific Remote Code Execution (RCE) vulnerabilities in Apache Struts (CVE-2017-5638, CVE-2017-9805) and explains how Cloudflare's Web Application Firewall (WAF) rules, such as rule 100054 in Cloudflare Specials, protect against these exploits. It also discusses SQL Injection (SQLi) attacks, providing examples of how they work and highlighting the volume of such attacks seen on the Cloudflare network, particularly against WordPress sites. The post emphasizes the role of the WAF in virtual patching these vulnerabilities to protect customers.