CVE-2017-16248

CVE-2017-16248

The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a ‘.’ character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a ‘.’ character.

Source: CVE-2017-16248

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다