Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown

CVE-2019-19886

Disclosure Date: February 28, 2019 (last updated February 21, 2025)
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.
Attacker Value
Unknown

CVE-2018-16384

Disclosure Date: September 03, 2018 (last updated November 27, 2024)
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.
Attacker Value
Unknown

CVE-2018-13065

Disclosure Date: July 03, 2018 (last updated November 08, 2023)
ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured
0
Attacker Value
Unknown

CVE-2013-5705

Disclosure Date: April 15, 2014 (last updated October 05, 2023)
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
0
Attacker Value
Unknown

CVE-2013-2765

Disclosure Date: July 15, 2013 (last updated October 05, 2023)
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
0
Attacker Value
Unknown

CVE-2013-1915

Disclosure Date: April 25, 2013 (last updated October 05, 2023)
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
0
Attacker Value
Unknown

CVE-2012-4528

Disclosure Date: December 28, 2012 (last updated October 05, 2023)
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
0
Attacker Value
Unknown

CVE-2009-5031

Disclosure Date: July 22, 2012 (last updated October 04, 2023)
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
0
Attacker Value
Unknown

CVE-2012-2751

Disclosure Date: July 22, 2012 (last updated November 08, 2023)
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.
0
Attacker Value
Unknown

CVE-2009-1903

Disclosure Date: June 03, 2009 (last updated October 04, 2023)
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
0