Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-1359

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.224
EPSS Ranking 95.6%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2007-1359


Contact Us

Shodan ® - All rights reserved