PT-1998-1219 · Eperl · Eperl

Published

1998-07-07

·

Updated

2016-10-18

·

CVE-1999-1437

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ePerl version 2.2.12
Description The issue allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to "bar.phtml".
Recommendations For ePerl version 2.2.12, consider restricting access to the bar.phtml file until a patch is available. Avoid using full pathnames as arguments to bar.phtml to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1437

Affected Products

Eperl