CVE-2009-5031
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request…
Does this matter?
Lower severity and a low EPSS score (2.93%). Track it; it rarely justifies an emergency change on its own.
Description
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.93% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- trustwave/modsecurity · opensuse/opensuse
- Source
- secalert@redhat.com
References
- http://blog.ivanristic.com/2012/06/modsecurity-and-modsecurity-core-rule-set-multipart-bypasses.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00031.htmlMailing List, Third Party Advisory
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.6.x/CHANGESBroken Link
- http://secunia.com/advisories/49576Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/06/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/06/22/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/54156Third Party Advisory, VDB Entry
- http://www.suspekt.org/downloads/POC2009-ShockingNewsInPHPExploitation.pdfThird Party Advisory
- https://www.modsecurity.org/fisheye/browse/modsecurity/m2/branches/2.5.x/apache2/msc_multipart.c?r2=1419&r1=1366Broken Link
- http://blog.ivanristic.com/2012/06/modsecurity-and-modsecurity-core-rule-set-multipart-bypasses.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00031.htmlMailing List, Third Party Advisory
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.6.x/CHANGESBroken Link
- http://secunia.com/advisories/49576Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/06/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/06/22/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/54156Third Party Advisory, VDB Entry
- http://www.suspekt.org/downloads/POC2009-ShockingNewsInPHPExploitation.pdfThird Party Advisory
- https://www.modsecurity.org/fisheye/browse/modsecurity/m2/branches/2.5.x/apache2/msc_multipart.c?r2=1419&r1=1366Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.