First published: Fri Dec 28 2012(Updated: )
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trustwave ModSecurity | <2.7.0 | |
openSUSE openSUSE | =11.4 | |
openSUSE openSUSE | =12.2 | |
openSUSE openSUSE | =12.3 | |
Fedoraproject Fedora | =18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.