CVE-2012-2751
Publication date 22 July 2012
Last updated 24 July 2024
Ubuntu priority
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.
From the Ubuntu Security Team
ModSecurity Multipart Quote Parsing Security Bypass Vulnerability
Status
Package | Ubuntu Release | Status |
---|---|---|
libapache-mod-security | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
modsecurity-apache | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|