ModSecurity POST Parameters Security Bypass Vulnerability
BID:56096
Info
ModSecurity POST Parameters Security Bypass Vulnerability
| Bugtraq ID: | 56096 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4528 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2012 12:00AM |
| Updated: | Apr 13 2015 08:48PM |
| Credit: | Bernhard Mueller |
| Vulnerable: |
SuSE openSUSE 11.4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: | |
Discussion
ModSecurity POST Parameters Security Bypass Vulnerability
ModSecurity is prone to a security-bypass vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits can allow attackers to bypass filtering rules; this may aid in further attacks.
ModSecurity 2.6.8 is vulnerable; other versions may also be affected.
ModSecurity is prone to a security-bypass vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits can allow attackers to bypass filtering rules; this may aid in further attacks.
ModSecurity 2.6.8 is vulnerable; other versions may also be affected.
Exploit / POC
ModSecurity POST Parameters Security Bypass Vulnerability
An attacker can exploit this issue using standard tools.
The following example data is available:
An attacker can exploit this issue using standard tools.
The following example data is available:
Solution / Fix
ModSecurity POST Parameters Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva apache-mod_security-2.6.1-1.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.6.1-1.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva apache-mod_security-2.6.1-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.6.1-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva apache-mod_security-2.5.12-0.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.5.12-0.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva apache-mod_security-2.6.3-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.6.3-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva apache-mod_security-2.5.12-0.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.5.12-0.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
ModSecurity POST Parameters Security Bypass Vulnerability
References:
References:
- ModSecurity Homepage (Trustwave)