vendor:
mod_security
by:
Unknown
5.5
CVSS
MEDIUM
Bypass
20
CWE
Product Name: mod_security
Affected Version From: mod_security <= 2.1.0
Affected Version To: mod_security <= 2.1.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
mod_security <= 2.1.0 (ASCIIZ byte) POST Rules Bypass Vulnerability
mod_security <= 2.1.0 is vulnerable to a bypass vulnerability where ASCIIZ bytes in POST data of the application/x-www-form-urlencoded content-type are not properly handled, allowing an attacker to bypass security rules. This vulnerability occurs due to a mismatch between the RFC-defined rules followed by mod_security and the actual behavior of HTTP request parsers in scripting languages like Perl, Python, Java, and PHP.
Mitigation:
Upgrade to a version of mod_security greater than 2.1.0.