9.8
CVSSv3

CVE-2011-2767

Published: 26/08/2018 Updated: 07/11/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

mod_perl 2.0 up to and including 2.0.10 allows malicious users to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache mod perl

debian debian linux 8.0

redhat enterprise linux 7.4

redhat enterprise linux 7.0

redhat enterprise linux 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux 6.7

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux 7.3

redhat enterprise linux 7.5

redhat enterprise linux 7.6

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

Debian Bug report logs - #644169 libapache2-mod-perl2: PerlOptions -Sections not permitted in server config, but should be Package: libapache2-mod-perl2; Maintainer for libapache2-mod-perl2 is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libapache2-mod-perl2 is src:libapache2-mod-perl2 (PTS, buildd, p ...
mod_perl could be made to run programs contrary to expectations ...
mod_perl could be made to run programs contrary to expectations ...
Synopsis Important: rh-perl526-mod_perl security update Type/Severity Security Advisory: Important Topic An update for rh-perl526-mod_perl is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Important: mod_perl security update Type/Severity Security Advisory: Important Topic An update for mod_perl is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base scor ...
Synopsis Important: rh-perl524-mod_perl security update Type/Severity Security Advisory: Important Topic An update for rh-perl524-mod_perl is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
mod_perl allows attackers to execute arbitrary Perl code by placing it in a user-owned htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user accou ...