bugs.debian.orgConfirmation
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629511 CVE-2011-2201
Perl Data::FormValidator 4.66 Module - 'results()' Security Bypass
Record summary
CVE-2011-2201 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPerl Data::FormValidator 4.66 Module - 'results()' Security BypassExploitDB exploitby dstNot analyzed1 file
References
9FEDORA-2011-11680Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065416.html [oss-security] 20110612 CVE Request -- Data-FormValidator -- Reports invalid field as valid when untaint_all_constraints usedmailing list
http://www.openwall.com/lists/oss-security/2011/06/12/3 [oss-security] 20110613 Re: CVE Request -- Data-FormValidator -- Reports invalid field as valid when untaint_all_constraints usedmailing list
http://www.openwall.com/lists/oss-security/2011/06/13/13 [oss-security] 20110613 Re: CVE Request -- Data-FormValidator -- Reports invalid field as valid when untaint_all_constraints usedmailing list
http://www.openwall.com/lists/oss-security/2011/06/13/5 48167vdb entry
http://www.securityfocus.com/bid/48167 bugzilla.redhat.comConfirmation
https://bugzilla.redhat.com/show_bug.cgi?id=712694 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-2201 rt.cpan.orgConfirmation
https://rt.cpan.org/Public/Bug/Display.html?id=61792