Описание
HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend.
For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.
Ссылки
- Patch
- Third Party Advisory
- ProductRelease Notes
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.09 (включая)
cpe:2.3:a:tokuhirom:http\:\:session2:*:*:*:*:*:perl:*:*
EPSS
Процентиль: 32%
0.00404
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 6.5
github
4 месяца назад
HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.
EPSS
Процентиль: 32%
0.00404
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo