Логотип exploitDog
bind:"CVE-2010-2761" OR bind:"CVE-2010-4410" OR bind:"CVE-2011-1487"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2010-2761" OR bind:"CVE-2010-4410" OR bind:"CVE-2011-1487"

Количество 18

Количество 18

oracle-oval логотип

ELSA-2011-0558

около 14 лет назад

ELSA-2011-0558: perl security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-1797

больше 13 лет назад

ELSA-2011-1797: perl security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2010-2761

больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2010-2761

больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2761

больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2761

больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.p ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-8x6h-gq6j-8x3j

около 3 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

EPSS: Низкий
ubuntu логотип

CVE-2011-1487

около 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2011-1487

около 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2011-1487

около 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-1487

около 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.1 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4410

больше 14 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2010-4410

больше 14 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4410

больше 14 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4410

больше 14 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm befo ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-j9hm-95rh-8hr5

около 3 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

EPSS: Низкий
github логотип

GHSA-63qf-cwcv-ff3r

около 3 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

EPSS: Низкий
fstec логотип

BDU:2016-02231

около 14 лет назад

Уязвимость интерпретатора Perl, позволяющая нарушителю внедрить произвольный код

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2011-0558

ELSA-2011-0558: perl security and bug fix update (MODERATE)

около 14 лет назад
oracle-oval логотип
ELSA-2011-1797

ELSA-2011-1797: perl security update (MODERATE)

больше 13 лет назад
ubuntu логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.p ...

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
github логотип
GHSA-8x6h-gq6j-8x3j

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

3%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
5%
Низкий
около 14 лет назад
redhat логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 2.6
5%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
5%
Низкий
около 14 лет назад
debian логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.1 ...

CVSS2: 5
5%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
redhat логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm befo ...

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
github логотип
GHSA-j9hm-95rh-8hr5

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

5%
Низкий
около 3 лет назад
github логотип
GHSA-63qf-cwcv-ff3r

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

1%
Низкий
около 3 лет назад
fstec логотип
BDU:2016-02231

Уязвимость интерпретатора Perl, позволяющая нарушителю внедрить произвольный код

CVSS2: 5
5%
Низкий
около 14 лет назад

Уязвимостей на страницу