Описание
The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.
Ссылки
- ExploitPatch
- ExploitPatch
- ExploitPatch
- ExploitPatch
- Exploit
- ExploitPatch
- Exploit
- ExploitPatch
- ExploitPatch
- ExploitPatch
- ExploitPatch
- Exploit
- ExploitPatch
- Exploit
Уязвимые конфигурации
Одновременно
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.
The Data::FormValidator module 4.66 and earlier for Perl, when untaint ...
The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.
EPSS
4.3 Medium
CVSS2