[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2018-1085 --- mod24_perl, mod_perl

ID: oval:org.secpod.oval:def:1600934Date: (C)2018-10-05   (M)2023-11-09
Class: PATCHFamily: unix




mod_perl allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.

Platform:
Amazon Linux AMI
Product:
mod24_perl
mod_perl
Reference:
ALAS-2018-1085
CVE-2011-2767
CVE    1
CVE-2011-2767
CPE    3
cpe:/o:amazon:linux
cpe:/a:apache:mod_perl
cpe:/a:apache:mod24_perl

© SecPod Technologies