An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-4935 An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T23:57:37.912Z

Reserved: 2019-07-09T00:00:00

Link: CVE-2019-13464

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-09T19:15:12.560

Modified: 2024-11-21T04:24:57.420

Link: CVE-2019-13464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.