CVE-2011-2201 – Perl Data::FormValidator 4.66 Module - 'results()' Security Bypass
https://notcve.org/view.php?id=CVE-2011-2201
The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input. El módulo Data::FormValidator v4.66 y anteriores para Perl, cuando untaint_all_constraints está activada, no conserva correctamente el atributo taint de los datos, lo que podría permitir a atacantes remotos evitar el mecanismo de protección ante corrupción de datos a través de un formulario de entrada. • https://www.exploit-db.com/exploits/35836 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629511 http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065416.html http://www.openwall.com/lists/oss-security/2011/06/12/3 http://www.openwall.com/lists/oss-security/2011/06/13/13 http://www.openwall.com/lists/oss-security/2011/06/13/5 http://www.securityfocus.com/bid/48167 https://bugzilla.redhat.com/show_bug.cgi?id=712694 https://rt.cpan.org • CWE-264: Permissions, Privileges, and Access Controls •