CVE-2012-4528: Fedoraproject Fedora
Medium severity, CVSS 5.0. EPSS: 12.5% chance of exploitation in the next 30 days.
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
Affected products
- Fedoraproject Fedora: version 18 only
- Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
- Trustwave Modsecurity: before 2.7.0 (fixed in 2.7.0)
Published 2012-12-28. Last modified 2026-06-16.