|
|
| |
|
| |
libapache-mod-security: cross-site scripting
| Package(s): | libapache-mod-security |
CVE #(s): | CVE-2012-2751
|
| Created: | July 3, 2012 |
Updated: | December 24, 2012 |
| Description: |
From the Debian advisory:
Qualys Vulnerability & Malware Research Labs discovered a vulnerability in
ModSecurity, a security module for the Apache webserver. In situations where
both 'Content:Disposition: attachment' and 'Content-Type: multipart' were
present in HTTP headers, the vulernability could allow an attacker to bypass
policy and execute cross-site script (XSS) attacks through properly crafted
HTML documents. |
| Alerts: |
|
( Log in to post comments)
|
|
|