Логотип exploitDog
bind:"CVE-2010-2761" OR bind:"CVE-2010-4410" OR bind:"CVE-2011-1487"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2010-2761" OR bind:"CVE-2010-4410" OR bind:"CVE-2011-1487"

Количество 18

Количество 18

oracle-oval логотип

ELSA-2011-0558

около 14 лет назад

ELSA-2011-0558: perl security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-1797

больше 13 лет назад

ELSA-2011-1797: perl security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2010-2761

больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2010-2761

почти 15 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2761

больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2761

больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.p ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-8x6h-gq6j-8x3j

около 3 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

EPSS: Низкий
ubuntu логотип

CVE-2011-1487

больше 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2011-1487

больше 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2011-1487

больше 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-1487

больше 14 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.1 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4410

больше 14 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2010-4410

почти 15 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4410

больше 14 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4410

больше 14 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm befo ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-j9hm-95rh-8hr5

около 3 лет назад

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

EPSS: Низкий
github логотип

GHSA-63qf-cwcv-ff3r

около 3 лет назад

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

EPSS: Низкий
fstec логотип

BDU:2016-02231

больше 14 лет назад

Уязвимость интерпретатора Perl, позволяющая нарушителю внедрить произвольный код

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2011-0558

ELSA-2011-0558: perl security and bug fix update (MODERATE)

около 14 лет назад
oracle-oval логотип
ELSA-2011-1797

ELSA-2011-1797: perl security update (MODERATE)

больше 13 лет назад
ubuntu логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
3%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.p ...

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
github логотип
GHSA-8x6h-gq6j-8x3j

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

3%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
4%
Низкий
больше 14 лет назад
redhat логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 2.6
4%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS2: 5
4%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-1487

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.1 ...

CVSS2: 5
4%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
redhat логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm befo ...

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
github логотип
GHSA-j9hm-95rh-8hr5

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

4%
Низкий
около 3 лет назад
github логотип
GHSA-63qf-cwcv-ff3r

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

1%
Низкий
около 3 лет назад
fstec логотип
BDU:2016-02231

Уязвимость интерпретатора Perl, позволяющая нарушителю внедрить произвольный код

CVSS2: 5
4%
Низкий
больше 14 лет назад

Уязвимостей на страницу