CVE-2007-1359
Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.
- Affected products
- Modsecurity, Php
- Mod Security
- = 1.7, 1.7.1, 1.7.2, 1.7.4, 1.7.5, 1.9.4, 2.1
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 6.6% (93th percentile)
- NVD status
- Modified
- Published
- 2007-03-08
CVE-2007-1359 at NVD
1 known exploit for CVE-2007-1359
Proof-of-concept code and exploit modules indexed by Sploitus