PT-2011-3240 · Mojolicious · Mojolicious

Vti

·

Published

2011-04-29

·

Updated

2017-08-17

·

CVE-2011-1589

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mojolicious versions prior to 1.16
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by including a %2f..%2f (encoded slash dot dot slash) in a URI.
Recommendations For versions prior to 1.16, update to version 1.16 or later to resolve the issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1589
DSA-2221-1

Affected Products

Mojolicious