Unrated severityNVD Advisory· Published Apr 15, 2014· Updated May 6, 2026
CVE-2013-5705
CVE-2013-5705
Description
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
Affected products
3cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/SpiderLabs/ModSecurity/commit/f8d441cd25172fdfe5b613442fedfc0da3cc333dnvdPatchThird Party Advisory
- martin.swende.se/blog/HTTPChunked.htmlnvdExploitThird Party Advisory
- www.debian.org/security/2014/dsa-2991nvdThird Party Advisory
News mentions
0No linked articles in our index yet.