7.5
CVSSv2

CVE-2011-2766

Published: 23/09/2011 Updated: 08/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The FCGI (aka Fast CGI) module 0.70 up to and including 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote malicious users to bypass authentication via crafted HTTP headers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fast cgi project fast cgi

debian debian linux 5.0

debian debian linux 6.0

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #607479 libfcgi-perl: [CVE-2011-2766] After reloading some environment vars become constants, that will be used if not overruled by the headers of new requests Package: libfcgi-perl; Maintainer for libfcgi-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libfcgi-perl is s ...
The FCGI (aka Fast CGI) module 070 through 073 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers ...