CVE-2009-1902
ModSecurity < 2.5.9 - Denial of Service via Multipart Form Data Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1902. PoCs published by Juan Galiana Lara.
AI-analyzed exploit summary This is a vulnerability writeup for CVE-2009-1902, detailing a remote Denial of Service (DoS) vulnerability in ModSecurity versions < 2.5.9. The vulnerability arises from insufficient input sanitization in the multipart processor, leading to a segmentation fault when processing crafted multipart/form-data requests.
Description
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference.
Exploits (1)
This is a vulnerability writeup for CVE-2009-1902, detailing a remote Denial of Service (DoS) vulnerability in ModSecurity versions < 2.5.9. The vulnerability arises from insufficient input sanitization in the multipart processor, leading to a segmentation fault when processing crafted multipart/form-data requests.