CyberSec.Space Logo
Back to CVE Browser

CVE-2019-13464

HIGH
7.5
CVSS Severity Score
EPSS Score0.0890%
EPSS Percentile31.18th
PublishedJul 9, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

Affected Platforms (CPE)

πŸ“¦
Modsecurity

Owasp Modsecurity Core Rule Set

= 3.0.2

References & Advisories

Related Vulnerabilities