Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ModSecurity 安全漏洞
Vulnerability Description
ModSecurity是一个入侵检测、阻止的引擎可以作为Apache Web服务器的一个模块或单独的应用程序来运行,为增强Web应用程序的安全性和保护Web应用程序避免遭受来自已知与未知的攻击。 ModSecurity 2.9.6之前版本和3.0.8之前的3.x版本存在安全漏洞,该漏洞源于HTTP多部分请求被错误地解析并且可以绕过Web应用程序防火墙。
CVSS Information
N/A
Vulnerability Type
N/A