CVE-2013-5705
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
- Affected products
- Alt Linux, Modsecurity, Suse
- Trustwave Modsecurity
- < 2.7.6
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 2.7% (85th percentile)
- NVD status
- Modified
- Published
- 2014-04-15
CVE-2013-5705 at NVD
1 known exploit for CVE-2013-5705
Proof-of-concept code and exploit modules indexed by Sploitus