PT-2001-1914 · Eperl · Eperl
Published
2001-10-18
·
Updated
2017-10-10
·
CVE-2001-0733
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
ePerl versions 2.2.14 and earlier
Description:
The issue allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive. This directive can reference a file containing malicious code, enabling its execution.
Recommendations:
For versions 2.2.14 and earlier, consider restricting access to the
sinclude directive until a patch is available. As a temporary workaround, avoid using the sinclude directive in sensitive environments to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eperl