漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OWASP ModSecurity Core Rule Set 代码问题漏洞
Vulnerability Description
OWASP ModSecurity Core Rule Set(CRS)是一组用于ModSecurity或兼容的Web应用程序防火墙的通用攻击检测规则。 OWASP ModSecurity CRS 3.0.2版本中存在安全漏洞,该漏洞源于程序将‘.’自动转换成’_‘。攻击者可利用该漏洞绕过PHP Script Uploads策略。
CVSS Information
N/A
Vulnerability Type
N/A