CVE-2012-4528: Medium severity modsecurity vulnerability
The modsecurity2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4528?
CVE-2012-4528 has a moderate severity rating as it can allow remote attacks that bypass security rules.
How do I fix CVE-2012-4528?
You can mitigate CVE-2012-4528 by upgrading the mod_security2 module to version 2.7.0 or later.
What systems are affected by CVE-2012-4528?
CVE-2012-4528 affects versions of the mod_security2 module before 2.7.0 on various distributions including openSUSE and Fedora.
Can CVE-2012-4528 lead to data exposure?
Yes, CVE-2012-4528 can lead to unauthorized delivery of arbitrary POST data, potentially exposing sensitive information.
Is CVE-2012-4528 being actively exploited?
While there have been reports of the vulnerability, active exploitation is not widely documented.