Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-4528Modsecurity vulnerability

7 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
11.5%
top 6.38%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 28
Latest updateMay 13

Description

The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDopensuse/opensuse11.4, 12.2, 12.3+2

Also affects: Fedora 18

🔴Vulnerability Details

3
GHSA
GHSA-v835-w774-qhww: The mod_security2 module before 22022-05-13
CVEList
CVE-2012-4528: The mod_security2 module before 22012-12-28
OSV
CVE-2012-4528: The mod_security2 module before 22012-12-28

💥Exploits & PoCs

1
Exploit-DB
ModSecurity - 'POST' Security Bypass2012-10-17

📋Vendor Advisories

1
Debian
CVE-2012-4528: modsecurity-apache - The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote a...2012

💬Community

1
Bugzilla
CVE-2012-4528 mod_security: multipart/invalid part ruleset bypass2012-10-17
CVE-2012-4528 — Trustwave Modsecurity vulnerability | cvebase