7.5
CVSSv2

CVE-1999-1437

Published: 07/07/1998 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ePerl 2.2.12 allows remote malicious users to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.

Vulnerable Product Search on Vulmon Subscribe to Product

ralf s. engelschall eperl 2.2.12

Exploits

source: wwwsecurityfocuscom/bid/151/info A bug exists in ePerl's handling of the ISINDEX queries When ISINDEX is used, the query is passed on the command line by the web server This would allow an attacker to execute arbitrary code via the ePerl interpreter, with none of the restrictions enforced normally In addition, this allows for t ...