CVE-2012-6329

Scores

EPSS

0.820high82.0%
0%20%40%60%80%100%

Percentile: 82.0%

CVSS

5.1medium2.0
0246810

CVSS Score: 5.1/10

All CVSS Scores

CVSS 2.0
5.1

Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Description

The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhat

CWEs

CWE-94

Related Vulnerabilities

Exploits

Exploit ID: 23579

Source: exploitdb

URL: https://www.exploit-db.com/exploits/23579

Exploit ID: 23580

Source: exploitdb

URL: https://www.exploit-db.com/exploits/23580

Vulnerable Software (6)

Type: Configuration

Product: foswiki

Operating System: debian

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: perl

Operating System: rhel 5

Trait:
{  "fixed": "5.8.8-40.el5_9"}

Source: redhat

Type: Configuration

Product: perl

Operating System: rhel 6

Trait:
{  "fixed": "5.10.1-130.el6_4"}

Source: redhat

Type: Configuration

Product: perl

Operating System: debian

Trait:
{  "fixed": "5.14.2-16"}

Source: debian

Type: Configuration

Product: perl

Operating System: debian squeeze 6

Trait:
{  "fixed": "5.10.1-17squeeze5"}

Source: debian

Type: Configuration

Vendor: *

Product: perl

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*",      "versionEndIncluding": "5.16.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:perl:perl:5....

Source: nvd

End of list