OWASP ModSecurity Core Rule Set(CRS)是一组用于ModSecurity或兼容的Web应用程序防火墙的通用攻击检测规则。 OWASP ModSecurity Core Rule Set (CRS)存在安全漏洞,该漏洞源于字符集接受头字段,导致响应规则集绕过。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OWASP | ModSecurity Core Rule Set | 3.0.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39958 | 7.5 HIGH | Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header sub |
| CVE-2022-39955 | 7.3 HIGH | Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially craft |
| CVE-2022-39956 | 7.3 HIGH | Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests us |
No comments yet