ZeroHour

CVE-2019-13464

PoC
CVSS 3.0
7.5 high
EPSS
1%p72
Published
()
Modified
Description

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

Vendors
modsecurity
Products
owasp modsecurity core rule set
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.