Sploitus

CVE-2007-1359

1 known exploit for CVE-2007-1359

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.

Affected products
Modsecurity, Php
Mod Security
= 1.7, 1.7.1, 1.7.2, 1.7.4, 1.7.5, 1.9.4, 2.1
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
6.6% (93th percentile)
NVD status
Modified
Published
2007-03-08
CVE-2007-1359 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-1359

Proof-of-concept code and exploit modules indexed by Sploitus