apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
References
Link | Resource |
---|---|
http://martin.swende.se/blog/HTTPChunked.html | Exploit Third Party Advisory |
https://github.com/SpiderLabs/ModSecurity/commit/f8d441cd25172fdfe5b613442fedfc0da3cc333d | Patch Third Party Advisory |
http://www.debian.org/security/2014/dsa-2991 | Third Party Advisory |
Information
Published : 2014-04-15 03:55
Updated : 2021-02-12 09:26
NVD link : CVE-2013-5705
Mitre link : CVE-2013-5705
JSON object : View
CWE
Products Affected
trustwave
- modsecurity
debian
- debian_linux