Back to Database
Status published
Medium
CVE-2013-5705
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass...
Vulnerability Description
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-5705
Credits & Attribution
No credits recorded in the NVD database.
References
More from trustwave
View All →CVE-2017-18001
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers...
Critical
9.8
CVE-2014-2727
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command...
Critical
9.8
CVE-2013-2765
The ModSecurity module before 2.7.4 for the Apache HTTP Server...
Medium
5
CVE-2013-1915
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files,...
High
7.5
CVE-2012-4528
The mod_security2 module before 2.7.0 for the Apache HTTP Server...
Medium
5
Affected Vendor
trustwave
View all reports →Affected Software
modsecurity, debian linux
Vulnerable Versions:
0, 7.0, 8.0
Timeline
Official Publish:
April 15th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.