Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 6 min 116 bronnen 1 kritiek 4 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2012-6141

HIGH · 7.5 CVSS Gepubliceerd: CWE-94

Beschrijving

The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request to (1) App::Session::Cookie or (2) App::Session::HTMLHidden, which is not properly handled when it is deserialized.

Vendors

Stephen Adkins

References