CVE-2019-13464
09.07.2019, 19:15
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.Enginsight
Vendor | Product | Version |
---|---|---|
modsecurity | owasp_modsecurity_core_rule_set | 3.0.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
modsecurity |
| ||||||||||||||||||||||||||||||
modsecurity-crs |
|
Common Weakness Enumeration