PoC Index

CVE-2011-1487

MEDIUM 5.0EPSS 8.7%

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
8.71% chance of exploitation in the next 30 days, 95th percentile
Published
2011-04-11
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related