PT-2001-1914 · Eperl · Eperl

Published

2001-10-18

·

Updated

2017-10-10

·

CVE-2001-0733

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ePerl versions 2.2.14 and earlier
Description: The issue allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive. This directive can reference a file containing malicious code, enabling its execution.
Recommendations: For versions 2.2.14 and earlier, consider restricting access to the sinclude directive until a patch is available. As a temporary workaround, avoid using the sinclude directive in sensitive environments to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0733

Affected Products

Eperl