MEDIUM · 4.3

CVE-2009-5031

ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site script...

Vulnerability Description

ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
TrustwaveModsecurity< 2.5.11
OpensuseOpensuse11.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-5031?

CVE-2009-5031 is a vulnerability with a CVSS score of 4.3 (MEDIUM). ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site script...

How severe is CVE-2009-5031?

CVE-2009-5031 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-5031?

Check the references section above for vendor advisories and patch information. Affected products include: Trustwave Modsecurity, Opensuse Opensuse.