Back to search
CVE-2009-5031
Published: Jul 22, 2012
Modified: Aug 7, 2024
PUBLISHED
Description
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
openSUSE-SU-2013:1342
vendor-advisory
x_refsource_SUSE
54156
vdb-entry
x_refsource_BID
openSUSE-SU-2013:1331
vendor-advisory
x_refsource_SUSE
[oss-security] 20120621 Re: mod_security CVE request
mailing-list
x_refsource_MLIST
[oss-security] 20120621 mod_security CVE request
mailing-list
x_refsource_MLIST
49576
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2013:1336
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now