Количество 12
Количество 12
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection ...
openSUSE-SU-2026:21119-1
Security update for perl-HTTP-Daemon
SUSE-SU-2026:2442-1
Security update for perl-HTTP-Daemon
SUSE-SU-2026:2408-1
Security update for perl-HTTP-Daemon
GHSA-3hc6-3p33-wq57
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
ELSA-2026-36189
ELSA-2026-36189: perl-HTTP-Daemon security update (IMPORTANT)
ELSA-2026-36188
ELSA-2026-36188: perl-HTTP-Daemon security update (IMPORTANT)
ELSA-2026-36187
ELSA-2026-36187: perl-HTTP-Daemon security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() | CVSS3: 9.1 | 1% Низкий | 5 дней назад | |
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection ... | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21119-1 Security update for perl-HTTP-Daemon | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2442-1 Security update for perl-HTTP-Daemon | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2408-1 Security update for perl-HTTP-Daemon | 1% Низкий | около 2 месяцев назад | ||
GHSA-3hc6-3p33-wq57 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
ELSA-2026-36189 ELSA-2026-36189: perl-HTTP-Daemon security update (IMPORTANT) | 15 дней назад | |||
ELSA-2026-36188 ELSA-2026-36188: perl-HTTP-Daemon security update (IMPORTANT) | 25 дней назад | |||
ELSA-2026-36187 ELSA-2026-36187: perl-HTTP-Daemon security update (IMPORTANT) | 25 дней назад |
Уязвимостей на страницу