← Vulnerability feed

Vulnerability record · CVE-2007-1359 · published 8 March 2007

CVE-2007-1359: Mod security vulnerability

Mod Security · Mod Security

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.

6.8 CVSS 2.0 Medium EPSS 6.6% · top 6.4%
6.8CVSS 2.0 base score
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143
http://secunia.com/advisories/24373 Vendor Advisory
http://secunia.com/advisories/25316
http://secunia.com/advisories/31087
http://secunia.com/advisories/31113
http://www.gentoo.org/security/en/glsa/glsa-200705-17.xml
http://www.modsecurity.org/blog/archives/2007/03/modsecurity_asc.html
http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.html
http://www.osvdb.org/32778
http://www.php-security.org/MOPB/BONUS-12-2007.html ExploitVendor Advisory
http://www.securityfocus.com/bid/22831 Vendor Advisory
http://www.vupen.com/english/advisories/2007/0868
http://www.vupen.com/english/advisories/2008/2109/references
http://www.vupen.com/english/advisories/2008/2115
https://exchange.xforce.ibmcloud.com/vulnerabilities/32872
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143
http://secunia.com/advisories/24373 Vendor Advisory
http://secunia.com/advisories/25316
http://secunia.com/advisories/31087
http://secunia.com/advisories/31113
http://www.gentoo.org/security/en/glsa/glsa-200705-17.xml
http://www.modsecurity.org/blog/archives/2007/03/modsecurity_asc.html
http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.html
http://www.osvdb.org/32778
http://www.php-security.org/MOPB/BONUS-12-2007.html ExploitVendor Advisory
http://www.securityfocus.com/bid/22831 Vendor Advisory
http://www.vupen.com/english/advisories/2007/0868
http://www.vupen.com/english/advisories/2008/2109/references
http://www.vupen.com/english/advisories/2008/2115
https://exchange.xforce.ibmcloud.com/vulnerabilities/32872

Track CVE-2007-1359 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-1359), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.