CVE-2012-4528
Trustwave ModSecurity < 2.7.0 - Rule Bypass via Malformed Multipart Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4528. PoCs published by Bernhard Mueller.
AI-analyzed exploit summary This exploit demonstrates a security-bypass vulnerability in ModSecurity by using a malformed multipart/form-data POST request to bypass filtering rules. The PoC shows how an attacker can inject SQL payloads by manipulating the Content-Disposition header.
Description
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
Exploits (1)
This exploit demonstrates a security-bypass vulnerability in ModSecurity by using a malformed multipart/form-data POST request to bypass filtering rules. The PoC shows how an attacker can inject SQL payloads by manipulating the Content-Disposition header.