Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-1359
Description:Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.
Test IDs: 1.3.6.1.4.1.25623.1.0.58279  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-1359
BugTraq ID: 22831
http://www.securityfocus.com/bid/22831
http://www.gentoo.org/security/en/glsa/glsa-200705-17.xml
HPdes Security Advisory: HPSBMA02133
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143
HPdes Security Advisory: SSRT061201
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143
http://www.php-security.org/MOPB/BONUS-12-2007.html
http://www.osvdb.org/32778
http://secunia.com/advisories/24373
http://secunia.com/advisories/25316
http://secunia.com/advisories/31087
http://secunia.com/advisories/31113
http://www.vupen.com/english/advisories/2007/0868
http://www.vupen.com/english/advisories/2008/2109/references
http://www.vupen.com/english/advisories/2008/2115
XForce ISS Database: modsecurity-formurlencoded-security-bypass(32872)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32872




© 1998-2025 E-Soft Inc. All rights reserved.