{"id":"CVE-2013-5705","details":"apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.","modified":"2026-04-16T06:25:11.527904044Z","published":"2014-04-15T10:55:11Z","references":[{"type":"ADVISORY","url":"http://martin.swende.se/blog/HTTPChunked.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-2991"},{"type":"ADVISORY","url":"https://github.com/SpiderLabs/ModSecurity/commit/f8d441cd25172fdfe5b613442fedfc0da3cc333d"},{"type":"EVIDENCE","url":"http://martin.swende.se/blog/HTTPChunked.html"},{"type":"FIX","url":"https://github.com/SpiderLabs/ModSecurity/commit/f8d441cd25172fdfe5b613442fedfc0da3cc333d"}],"schema_version":"1.7.5"}