CVE-2013-1915
Publication date 25 April 2013
Last updated 24 July 2024
Ubuntu priority
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
Status
Package | Ubuntu Release | Status |
---|---|---|
libapache-mod-security | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
modsecurity-apache | ||
16.04 LTS xenial |
Fixed 2.6.6-6
|
|
14.04 LTS trusty |
Fixed 2.6.6-6
|
|