Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qm4-xr26-w9h5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

EPSS

Процентиль: 46%
0.00237
Низкий

7.5 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2 ...

EPSS

Процентиль: 46%
0.00237
Низкий

7.5 High

CVSS3

Дефекты

CWE-434