445
VMScore

CVE-2019-13464

Published: 09/07/2019 Updated: 15/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

modsecurity owasp modsecurity core rule set 3.0.2

Vendor Advisories

Debian Bug report logs - #943773 CVE-2019-13464 Package: modsecurity-crs; Maintainer for modsecurity-crs is Alberto Gonzalez Iniesta <agi@inittaborg>; Source for modsecurity-crs is src:modsecurity-crs (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 29 Oct 2019 16:45:02 UTC Severity ...