|
|
| |
|
| |
perl-Dancer: header injection
| Package(s): | perl-Dancer |
CVE #(s): | CVE-2012-5572
|
| Created: | June 13, 2013 |
Updated: | June 28, 2013 |
| Description: |
From the Red Hat Bugzilla entry:
A security flaw was found in the way Dancer.pm, lightweight yet powerful web application framework / Perl language module, performed sanitization of values to be used for cookie() and cookies() methods. A remote attacker could use this flaw to inject arbitrary headers into responses from (Perl) applications, that use Dancer.pm. |
| Alerts: |
|
( Log in to post comments)
|
|
|