CVE-2009-5031
Publication date 22 July 2012
Last updated 24 July 2024
Ubuntu priority
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
From the Ubuntu Security Team
ModSecurity Multipart Quote Parsing Security Bypass Vulnerability
Status
Package | Ubuntu Release | Status |
---|---|---|
libapache-mod-security | ||
modsecurity-apache | ||
Patch details
Package | Patch details |
---|---|
libapache-mod-security | |
modsecurity-apache |