CyberSec.Space Logo
返回 CVE 浏览器

CVE-2019-13464

HIGH
7.5
CVSS Severity Score
EPSS Score0.0890%
EPSS Percentile31.18th
Published2019年7月9日
Last Modified2024年11月21日

Vulnerability Description

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

Affected Platforms (CPE)

📦
Modsecurity

Owasp Modsecurity Core Rule Set

= 3.0.2

References & Advisories

相关漏洞威胁