PT-2011-3678 · Perl · Data::Formvalidator
Publicado
2011-09-14
·
Atualizado
2011-09-14
·
CVE-2011-2201
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Data::FormValidator versions 4.66 and earlier
Description
The issue concerns the Data::FormValidator module for Perl. When the untaint all constraints option is enabled, it fails to properly preserve the taint attribute of data. This could potentially allow remote attackers to bypass the taint protection mechanism by manipulating form input.
Recommendations
For versions 4.66 and earlier, consider disabling the untaint all constraints option as a temporary workaround until a patch is available. Restrict access to form input to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Data::Formvalidator