Owasp

Owasp Modsecurity Core Rule Set

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Published 20.09.2022 07:15:12
  • Last modified 21.11.2024 07:18:33

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited...

  • EPSS 0.09%
  • Published 20.09.2022 07:15:12
  • Last modified 21.11.2024 07:18:33

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MI...

  • EPSS 0.12%
  • Published 20.09.2022 07:15:12
  • Last modified 21.11.2024 07:18:33

The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset"...

  • EPSS 0.28%
  • Published 20.09.2022 07:15:12
  • Last modified 21.11.2024 07:18:33

The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, acc...

Exploit
  • EPSS 0.06%
  • Published 02.09.2022 18:15:11
  • Last modified 21.11.2024 05:13:21

Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injec...

Exploit
  • EPSS 0.38%
  • Published 05.11.2021 18:15:09
  • Last modified 21.11.2024 06:12:15

OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.

Exploit
  • EPSS 0.06%
  • Published 03.09.2018 02:29:00
  • Last modified 21.11.2024 03:52:38

A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.