Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1359

Опубликовано: 08 мар. 2007
Источник: nvd
CVSS2: 6.8
EPSS Средний

Описание

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mod_security:mod_security:1.7:*:*:*:*:*:*:*
cpe:2.3:a:mod_security:mod_security:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mod_security:mod_security:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mod_security:mod_security:1.7.4:*:*:*:*:*:*:*
cpe:2.3:a:mod_security:mod_security:1.7.5:*:*:*:*:*:*:*
cpe:2.3:a:mod_security:mod_security:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:mod_security:mod_security:2.1:*:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.23038
Средний

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
больше 18 лет назад

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.

debian
больше 18 лет назад

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlie ...

github
больше 3 лет назад

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.

EPSS

Процентиль: 96%
0.23038
Средний

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo