Back to Database
Status published
Medium
CVE-2011-1589
Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows...
Vulnerability Description
Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1589
Credits & Attribution
No credits recorded in the NVD database.
References
- http://perlninja.posterous.com/sharks-in-the-water
- http://www.debian.org/security/2011/dsa-2221
- http://search.cpan.org/CPAN/authors/id/K/KR/KRAIH/Mojolicious-1.16.tar.gz
- http://www.vupen.com/english/advisories/2011/1072
- https://github.com/kraih/mojo/issues/114
- http://openwall.com/lists/oss-security/2011/04/18/7
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058891.html
- http://secunia.com/advisories/44359
- https://github.com/kraih/mojo/commit/b09854988c5b5b6a2ba53cc8661c4b2677da3818
- http://secunia.com/advisories/44051
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622952
- http://www.vupen.com/english/advisories/2011/1093
- http://www.osvdb.org/71850
- http://openwall.com/lists/oss-security/2011/04/17/1
- http://www.securityfocus.com/bid/47402
- http://cpansearch.perl.org/src/KRAIH/Mojolicious-1.16/Changes
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66830
- http://openwall.com/lists/oss-security/2011/04/18/3
- https://bugzilla.redhat.com/show_bug.cgi?id=697229
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058885.html
More from mojolicious
View All →CVE-2021-47208
The Mojolicious module before 9.11 for Perl has a bug...
Unknown
0
CVE-2011-1841
Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious...
Medium
4.3
CVE-2010-4803
Mojolicious before 0.999927 does not properly implement HMAC-MD5 checksums, which...
Critical
10
CVE-2010-4802
Commands.pm in Mojolicious before 0.999928 does not properly perform CGI...
Critical
10
CVE-2009-5074
Unspecified vulnerability in the MojoX::Dispatcher::Static implementation in Mojolicious before 0.991250...
Critical
10
Affected Vendor
mojolicious
View all reports →Affected Software
mojolicious
Vulnerable Versions:
0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.9, 0.8006, 0.8007, 0.8008, 0.8009, 0.9001, 0.9002, 0.991231, 0.991232, 0.991233, 0.991234, 0.991235, 0.991236, 0.991237, 0.991238, 0.991239, 0.991240, 0.991241, 0.991242, 0.991243, 0.991244, 0.991245, 0.991246, 0.991250, 0.991251, 0.999901, 0.999902, 0.999903, 0.999904, 0.999905, 0.999906, 0.999907, 0.999908, 0.999909, 0.999910, 0.999911, 0.999912, 0.999913, 0.999914, 0.999920, 0.999921, 0.999922, 0.999923, 0.999924, 0.999925, 0.999926, 0.999927, 0.999928, 0.999929, 0.999930, 0.999931, 0.999932, 0.999933, 0.999934, 0.999935, 0.999936, 0.999937, 0.999938, 0.999939, 0.999940, 0.999941, 0.999950, 1.0, 1.1, 1.01, 1.11, 1.12, 1.13, 1.14, 1.15
Timeline
Official Publish:
April 29th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.