Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Catalyst-plugin-static-simple Project Subscribe
Filtered by product Catalyst-plugin-static-simple
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16248 1 Catalyst-plugin-static-simple Project 1 Catalyst-plugin-static-simple 2017-11-22 5.0 MEDIUM 7.5 HIGH
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.