CVE-2011-2201

Data::FormValidator <4.66 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-2201. PoCs published by dst.

AI-analyzed exploit summary This exploit demonstrates a security-bypass vulnerability in the Perl Data::FormValidator module. By leveraging a regex untainting issue, it bypasses constraint checks to validate input that should otherwise fail.

Description

The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dst · perlremotelinux
https://www.exploit-db.com/exploits/35836

This exploit demonstrates a security-bypass vulnerability in the Perl Data::FormValidator module. By leveraging a regex untainting issue, it bypasses constraint checks to validate input that should otherwise fail.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Data::FormValidator 4.66
No auth needed
Prerequisites: Perl environment with Data::FormValidator 4.66 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/48167
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/06/13/5
Exploit, Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/06/12/3
Exploit, Patch x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629511
Exploit, Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=712694
Exploit, Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/06/13/13

Scores

EPSS 0.1238
EPSS Percentile 94.1%

Details

CWE
CWE-264
Status published
Products (1)
mark_stosberg/data\ \ formvalidator (50 CPE variants)
Published Sep 14, 2011
Tracked Since Feb 18, 2026