CVE-2011-1487
The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
- Perl
- = 5.10.0, 5.10.1
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 8.7% (95th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2011-04-11
CVE-2011-1487 at NVD
1 known exploit for CVE-2011-1487
Proof-of-concept code and exploit modules indexed by Sploitus