Show filters
333 Total Results
Displaying 311-320 of 333
Sort by:
Attacker Value
Unknown

CVE-2002-1323

Disclosure Date: December 11, 2002 (last updated October 03, 2023)
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
0
Attacker Value
Unknown

CVE-2002-1271

Disclosure Date: November 12, 2002 (last updated October 03, 2023)
The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx.
0
Attacker Value
Unknown

CVE-2002-1196

Disclosure Date: October 28, 2002 (last updated October 03, 2023)
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.
0
Attacker Value
Unknown

CVE-2002-0924

Disclosure Date: October 04, 2002 (last updated October 03, 2023)
CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability.
0
Attacker Value
Unknown

CVE-2002-0495

Disclosure Date: August 12, 2002 (last updated February 14, 2024)
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
0
Attacker Value
Unknown

CVE-2002-0703

Disclosure Date: July 26, 2002 (last updated October 03, 2023)
An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data.
0
Attacker Value
Unknown

CVE-2002-0307

Disclosure Date: May 31, 2002 (last updated October 03, 2023)
Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's eval function.
0
Attacker Value
Unknown

CVE-2002-0245

Disclosure Date: May 29, 2002 (last updated October 03, 2023)
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's version name in the HTTP error message.
0
Attacker Value
Unknown

CVE-2001-0733

Disclosure Date: October 18, 2001 (last updated October 03, 2023)
The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code.
0
Attacker Value
Unknown

CVE-2001-0436

Disclosure Date: July 02, 2001 (last updated October 03, 2023)
dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.
0