CVE-2012-2751Cross-site Scripting in Modsecurity

9 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
1.9%
top 16.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 13

Description

ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDopensuse/opensuse11.4, 12.2, 12.3+2
NVDoracle/http_server11.1.1.6.0

Also affects: Debian Linux 6.0, 7.0

🔴Vulnerability Details

3
GHSA
GHSA-38m7-p7j8-c694: ModSecurity before 22022-05-13
CVEList
CVE-2012-2751: ModSecurity before 22012-07-22
OSV
CVE-2012-2751: ModSecurity before 22012-07-22

💥Exploits & PoCs

1
Exploit-DB
Parodia 6.8 - 'employer-profile.asp' SQL Injection2012-06-25

📋Vendor Advisories

1
Debian
CVE-2012-2751: modsecurity-apache - ModSecurity before 2.6.6, when used with PHP, does not properly handle single qu...2012

💬Community

3
Bugzilla
CVE-2012-2751 mod_security: Multipart bypass issue related to quote parsing2012-06-22
Bugzilla
CVE-2012-2751 mod_security: Multipart bypass issue related to quote parsing [fedora-all]2012-06-22
Bugzilla
CVE-2012-2751 mod_security: Multipart bypass issue related to quote parsing [epel-all]2012-06-22
CVE-2012-2751 — Cross-site Scripting in Modsecurity | cvebase