ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
| Software | From | Fixed in |
|---|---|---|
| trustwave / modsecurity | - | 2.5.11 |
| opensuse / opensuse | 12.3 | 12.3.x |
| opensuse / opensuse | 11.4 | 11.4.x |
| opensuse / opensuse | 12.2 | 12.2.x |