CVE-2011-1589 - CVE House
Back to Database
Status published Medium CVE-2011-1589

Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows...

Vulnerability Description

Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1589

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

mojolicious

View all reports →

Affected Software

mojolicious
Vulnerable Versions:
0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.9, 0.8006, 0.8007, 0.8008, 0.8009, 0.9001, 0.9002, 0.991231, 0.991232, 0.991233, 0.991234, 0.991235, 0.991236, 0.991237, 0.991238, 0.991239, 0.991240, 0.991241, 0.991242, 0.991243, 0.991244, 0.991245, 0.991246, 0.991250, 0.991251, 0.999901, 0.999902, 0.999903, 0.999904, 0.999905, 0.999906, 0.999907, 0.999908, 0.999909, 0.999910, 0.999911, 0.999912, 0.999913, 0.999914, 0.999920, 0.999921, 0.999922, 0.999923, 0.999924, 0.999925, 0.999926, 0.999927, 0.999928, 0.999929, 0.999930, 0.999931, 0.999932, 0.999933, 0.999934, 0.999935, 0.999936, 0.999937, 0.999938, 0.999939, 0.999940, 0.999941, 0.999950, 1.0, 1.1, 1.01, 1.11, 1.12, 1.13, 1.14, 1.15

Timeline

Official Publish: April 29th, 2011
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.