Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fgsch

#35520of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2019-13349
7.5
2019-07-09
Owasp · Owasp Modsecurity Core Rule Set · CVE-2019-13464
**Name of the Vulnerable Software and Affected Versions** OWASP ModSecurity Core Rule Set (CRS) version 3.0.2 **Description** An issue was discovered where the use of `X.Filename` instead of `X Filename` can bypass some PHP Script Uploads rules. This occurs because PHP automatically transforms dots into underscores in certain contexts where dots are invalid. **Recommendations** For OWASP ModSecurity Core Rule Set (CRS) version 3.0.2, consider using `X Filename` instead of `X.Filename` to prevent bypassing of PHP Script Uploads rules. As a temporary workaround, review and update the existing rules to ensure they are not relying on the incorrect transformation of dots to underscores.