Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-5031
HistoryJul 22, 2012 - 12:00 a.m.

CVE-2009-5031

2012-07-2200:00:00
ubuntu.com
ubuntu.com
11

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

68.2%

ModSecurity before 2.5.11 treats request parameter values containing single
quotes as files, which allows remote attackers to bypass filtering rules
and perform other attacks such as cross-site scripting (XSS) attacks via a
single quote in a request parameter in the Content-Disposition field of a
request with a multipart/form-data Content-Type header.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchlibapache-mod-security< 2.5.11-1UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

68.2%