Title : ModSecurity "SecCacheTransformations" Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-2795 CVE ID : CVE-2008-5676 CWE ID : CWE-264
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-13
Technical Description
A vulnerability has been identified in ModSecurity, which could be exploited by attackers to cause a denial of service or bypass security restrictions. This issue is caused by an unspecified error within transformation caching (when "SecCacheTransformations" is enabled), which could allow attackers to crash a vulnerable web server or evade ModSecurity.