Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ModSecurity 配置错误漏洞
Vulnerability Description
ModSecurity是一个入侵检测、阻止的引擎可以作为Apache Web服务器的一个模块或单独的应用程序来运行,为增强Web应用程序的安全性和保护Web应用程序避免遭受来自已知与未知的攻击。 ModSecurity 2.5.8之前版本存在配置错误漏洞。该漏洞源于PDF XSS保护特性允许远程攻击者通过不使用GET方法的PDF文件请求,导致拒绝服务(Apache httpd崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A