Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-6141

Опубликовано: 04 июн. 2014
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request to (1) App::Session::Cookie or (2) App::Session::HTMLHidden, which is not properly handled when it is deserialized.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:stephen_adkins:app\:\:context:0.01:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.93:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.95:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.96:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.961:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.962:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.963:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.964:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.965:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.966:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.967:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.968:*:*:*:*:perl:*:*
cpe:2.3:a:stephen_adkins:app\:\:context:0.9661:*:*:*:*:perl:*:*

EPSS

Процентиль: 81%
0.01618
Низкий

7.5 High

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
больше 3 лет назад

The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request to (1) App::Session::Cookie or (2) App::Session::HTMLHidden, which is not properly handled when it is deserialized.

EPSS

Процентиль: 81%
0.01618
Низкий

7.5 High

CVSS2

Дефекты

CWE-94