VulnerabilityModified
CVE-2012-4528
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
MEDIUM 5.0EPSS 12.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 12.51% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- trustwave/modsecurity · opensuse/opensuse · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093011.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00031.htmlMailing List, Third Party Advisory
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGESBroken Link
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/apache2/msc_multipart.c?sortby=date&r1=2081&r2=2080&pathrev=2081Broken Link
- http://mod-security.svn.sourceforge.net/viewvc/mod-security?view=revision&sortby=date&revision=2081Broken Link
- http://seclists.org/fulldisclosure/2012/Oct/113Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/10/18/14Mailing List, Third Party Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20121017-0_mod_security_ruleset_bypass.txtThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093011.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00031.htmlMailing List, Third Party Advisory
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGESBroken Link
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/apache2/msc_multipart.c?sortby=date&r1=2081&r2=2080&pathrev=2081Broken Link
- http://mod-security.svn.sourceforge.net/viewvc/mod-security?view=revision&sortby=date&revision=2081Broken Link
- http://seclists.org/fulldisclosure/2012/Oct/113Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/10/18/14Mailing List, Third Party Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20121017-0_mod_security_ruleset_bypass.txtThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.