Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-15392

Опубликовано: 17 июл. 2026
Источник: msrc
CVSS3: 7.7
EPSS Низкий

Описание

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location

EPSS

Процентиль: 6%
0.00163
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
28 дней назад

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory.

CVSS3: 6.3
redhat
28 дней назад

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory.

CVSS3: 7.7
nvd
28 дней назад

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory.

CVSS3: 7.7
debian
28 дней назад

DBD::File versions before 1.651 for Perl do not ensure the table file ...

suse-cvrf
20 дней назад

Security update for perl-DBI

EPSS

Процентиль: 6%
0.00163
Низкий

7.7 High

CVSS3