Lucene search

K
cve[email protected]CVE-2011-3597
HistoryJan 13, 2012 - 6:55 p.m.

CVE-2011-3597

2012-01-1318:55:03
CWE-20
web.nvd.nist.gov
41
cve-2011-3597
eval injection
vulnerability
perl
digest module
arbitrary command execution

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.3 High

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.6%

Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.

Affected configurations

NVD
Node
gisle_aasdigestMatch1.00
OR
gisle_aasdigestMatch1.01
OR
gisle_aasdigestMatch1.02
OR
gisle_aasdigestMatch1.03
OR
gisle_aasdigestMatch1.04
OR
gisle_aasdigestMatch1.05
OR
gisle_aasdigestMatch1.06
OR
gisle_aasdigestMatch1.07
OR
gisle_aasdigestMatch1.08
OR
gisle_aasdigestMatch1.09
OR
gisle_aasdigestMatch1.10
OR
gisle_aasdigestMatch1.11
OR
gisle_aasdigestMatch1.12
OR
gisle_aasdigestMatch1.13
OR
gisle_aasdigestMatch1.14
OR
gisle_aasdigestMatch1.15
OR
gisle_aasdigestMatch1.16

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.3 High

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.6%