CVE-2012-4528: Fedoraproject Fedora

Medium severity, CVSS 5.0. EPSS: 12.5% chance of exploitation in the next 30 days.

The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.

Affected products

  • Fedoraproject Fedora: version 18 only
  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Trustwave Modsecurity: before 2.7.0 (fixed in 2.7.0)

Published 2012-12-28. Last modified 2026-06-16.