PT-2012-1274 · Trustwave+2 · Modsecurity+2

Kurt Seifried

·

Published

2012-07-22

·

Updated

2024-06-15

·

CVE-2009-5031

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ModSecurity versions prior to 2.5.11
Description The issue allows remote attackers to bypass filtering rules by including a single quote in a request parameter within the Content-Disposition field of a request that has a multipart/form-data Content-Type header. This can lead to other attacks, such as cross-site scripting (XSS) attacks.
Recommendations For versions prior to 2.5.11, update to version 2.5.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the Content-Disposition field in requests with a multipart/form-data Content-Type header until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1387
CVE-2009-5031
OPENSUSE-SU-2024:10034-1

Affected Products

Alt Linux
Modsecurity
Suse