Filtered by vendor Catalyst-plugin-static-simple Project Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-16248 1 Catalyst-plugin-static-simple Project 1 Catalyst-plugin-static-simple 2024-08-05 N/A
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.