CVE-2012-2751: Debian Linux

Medium severity, CVSS 4.3. EPSS: 3.3% chance of exploitation in the next 30 days.

ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.

Affected products

  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Oracle HTTP Server: version 11.1.1.6.0 only
  • Trustwave Modsecurity: before 2.6.6 (fixed in 2.6.6)

Published 2012-07-22. Last modified 2026-06-16.