«
Expand/Collapse
110 items tagged "perl"
Related tags:
taint [+],
security vulnerability [+],
privilege escalation vulnerability [+],
header values [+],
header [+],
tcl [+],
postgresql [+],
scanner [+],
rdo [+],
target [+],
taint mode [+],
system administration utilities [+],
red [+],
protection security [+],
local privilege escalation [+],
lfi [+],
level programming language [+],
functions [+],
txt [+],
bugtraq [+],
usn [+],
shell [+],
new [+],
mdvsa [+],
digest [+],
cgi backdoor [+],
capability [+],
wrong number [+],
web application [+],
web [+],
security notice [+],
script [+],
red hat security [+],
race [+],
program [+],
plomp [+],
perl functions [+],
perl code [+],
number [+],
null pointer dereference [+],
null [+],
malformed requests [+],
linux environment [+],
kolkata [+],
hat [+],
grabber [+],
escalation [+],
condition [+],
based buffer overflow [+],
banner [+],
arp spoofer [+],
application [+],
windows kernel [+],
usa [+],
tcp session [+],
tcp [+],
tcl procedures [+],
tcl code [+],
ssl [+],
socket [+],
session [+],
perl hacker [+],
perl data [+],
perjack [+],
man in the middle attack [+],
keylogger [+],
kernel [+],
joe stewart tags [+],
joe stewart [+],
hex [+],
glob [+],
formvalidator [+],
encode max by mdh [+],
dsa [+],
decode [+],
data [+],
code execution [+],
module [+],
yaml libyaml [+],
yaml [+],
vectors [+],
temporary file [+],
slides [+],
short [+],
service vulnerability [+],
security weakness [+],
security [+],
retired [+],
regular expression [+],
rat [+],
random number [+],
question [+],
python [+],
processing [+],
par [+],
paper [+],
number values [+],
mysql [+],
mime [+],
links [+],
injection [+],
glsa [+],
fuzzy [+],
format string [+],
facebook [+],
expression [+],
denial of service [+],
creation vulnerability [+],
command line [+],
command [+],
cache cache [+],
cache [+],
safe [+],
reval [+],
restriction [+],
cgi [+],
vulnerability [+],
perl script [+],
perl cgi [+]
-
-
15:45
»
Packet Storm Security Advisories
Red Hat Security Advisory 2011-1797-01 - Perl is a high-level programming language commonly used for system administration utilities and web programming. It was found that the "new" constructor of the Digest module used its argument as part of the string expression passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary Perl code with the privileges of a Perl program that uses untrusted input as an argument to the constructor. It was found that the Perl CGI module used a hard-coded value for the MIME boundary string in multipart/x-mixed-replace content. A remote attacker could possibly use this flaw to conduct an HTTP response splitting attack via a specially-crafted HTTP request.
-
15:45
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2011-1797-01 - Perl is a high-level programming language commonly used for system administration utilities and web programming. It was found that the "new" constructor of the Digest module used its argument as part of the string expression passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary Perl code with the privileges of a Perl program that uses untrusted input as an argument to the constructor. It was found that the Perl CGI module used a hard-coded value for the MIME boundary string in multipart/x-mixed-replace content. A remote attacker could possibly use this flaw to conduct an HTTP response splitting attack via a specially-crafted HTTP request.
-
15:45
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2011-1797-01 - Perl is a high-level programming language commonly used for system administration utilities and web programming. It was found that the "new" constructor of the Digest module used its argument as part of the string expression passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary Perl code with the privileges of a Perl program that uses untrusted input as an argument to the constructor. It was found that the Perl CGI module used a hard-coded value for the MIME boundary string in multipart/x-mixed-replace content. A remote attacker could possibly use this flaw to conduct an HTTP response splitting attack via a specially-crafted HTTP request.
-
-
15:38
»
Packet Storm Security Advisories
Red Hat Security Advisory 2011-1424-01 - Perl is a high-level programming language commonly used for system administration utilities and web programming. A heap-based buffer overflow flaw was found in the way Perl decoded Unicode strings. An attacker could create a malicious Unicode string that, when decoded by a Perl program, would cause the program to crash or, potentially, execute arbitrary code with the permissions of the user running the program. It was found that the "new" constructor of the Digest module used its argument as part of the string expression passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary Perl code with the privileges of a Perl program that uses untrusted input as an argument to the constructor.
-
15:38
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2011-1424-01 - Perl is a high-level programming language commonly used for system administration utilities and web programming. A heap-based buffer overflow flaw was found in the way Perl decoded Unicode strings. An attacker could create a malicious Unicode string that, when decoded by a Perl program, would cause the program to crash or, potentially, execute arbitrary code with the permissions of the user running the program. It was found that the "new" constructor of the Digest module used its argument as part of the string expression passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary Perl code with the privileges of a Perl program that uses untrusted input as an argument to the constructor.
-
15:38
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2011-1424-01 - Perl is a high-level programming language commonly used for system administration utilities and web programming. A heap-based buffer overflow flaw was found in the way Perl decoded Unicode strings. An attacker could create a malicious Unicode string that, when decoded by a Perl program, would cause the program to crash or, potentially, execute arbitrary code with the permissions of the user running the program. It was found that the "new" constructor of the Digest module used its argument as part of the string expression passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary Perl code with the privileges of a Perl program that uses untrusted input as an argument to the constructor.
-
-
7:44
»
Packet Storm Security Tools
Short Fuzzy Rat is a web fuzzing script written in perl. It was inspired by Luca Carettoni's original fuzzing list of 879 attack vectors with 8 levels of recursion.
-
-
0:11
»
Packet Storm Security Recent Files
Plomp is a HTTP banner grabber script written in Perl that also sends malformed requests to the server in order to determine if the version information has been altered.
-
0:11
»
Packet Storm Security Tools
Plomp is a HTTP banner grabber script written in Perl that also sends malformed requests to the server in order to determine if the version information has been altered.
-
0:11
»
Packet Storm Security Misc. Files
Plomp is a HTTP banner grabber script written in Perl that also sends malformed requests to the server in order to determine if the version information has been altered.
-
7:55
»
Packet Storm Security Tools
This is a simple perl script called Viper LFI Scanner that enumerates local file inclusion attempts when given a specific target.
-
3:26
»
Packet Storm Security Tools
This is a simple perl script called Viper LFI Scanner that enumerates local file inclusion attempts when given a specific target.
-
-
15:28
»
Packet Storm Security Advisories
When given a wrong number of arguments, a number of perl functions will attempt to read memory from an unmapped location, resulting in a deterministic crash.
-
15:28
»
Packet Storm Security Recent Files
When given a wrong number of arguments, a number of perl functions will attempt to read memory from an unmapped location, resulting in a deterministic crash.
-
15:28
»
Packet Storm Security Misc. Files
When given a wrong number of arguments, a number of perl functions will attempt to read memory from an unmapped location, resulting in a deterministic crash.
-
-
8:44
»
Packet Storm Security Advisories
Ubuntu Security Notice 1129-1 - It was discovered that the Safe.pm Perl module incorrectly handled Safe::reval and Safe::rdo access restrictions. It was discovered that the CGI.pm Perl module incorrectly handled certain MIME boundary strings. It was discovered that the CGI.pm Perl module incorrectly handled newline characters. It was discovered that the lc, lcfirst, uc, and ucfirst functions did not properly apply the taint attribute when processing tainted input.
-
8:44
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1129-1 - It was discovered that the Safe.pm Perl module incorrectly handled Safe::reval and Safe::rdo access restrictions. It was discovered that the CGI.pm Perl module incorrectly handled certain MIME boundary strings. It was discovered that the CGI.pm Perl module incorrectly handled newline characters. It was discovered that the lc, lcfirst, uc, and ucfirst functions did not properly apply the taint attribute when processing tainted input.
-
8:44
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1129-1 - It was discovered that the Safe.pm Perl module incorrectly handled Safe::reval and Safe::rdo access restrictions. It was discovered that the CGI.pm Perl module incorrectly handled certain MIME boundary strings. It was discovered that the CGI.pm Perl module incorrectly handled newline characters. It was discovered that the lc, lcfirst, uc, and ucfirst functions did not properly apply the taint attribute when processing tainted input.
-
-
12:00
»
Packet Storm Security Recent Files
Ubuntu Security Notice 942-1 - It was discovered that the Safe.pm module as used by PostgreSQL did not properly restrict PL/perl procedures. If PostgreSQL was configured to use Perl stored procedures, a remote authenticated attacker could exploit this to execute arbitrary Perl code. It was discovered that PostgreSQL did not properly check permissions to restrict PL/Tcl procedures. If PostgreSQL was configured to use Tcl stored procedures, a remote authenticated attacker could exploit this to execute arbitrary Tcl code.
-
12:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 942-1 - It was discovered that the Safe.pm module as used by PostgreSQL did not properly restrict PL/perl procedures. If PostgreSQL was configured to use Perl stored procedures, a remote authenticated attacker could exploit this to execute arbitrary Perl code. It was discovered that PostgreSQL did not properly check permissions to restrict PL/Tcl procedures. If PostgreSQL was configured to use Tcl stored procedures, a remote authenticated attacker could exploit this to execute arbitrary Tcl code.
-
-
12:00
»
Packet Storm Security Advisories
Perl Cache-Cache version 1.06 suffers from an insecure permission vulnerability.
-
-
17:00
»
Packet Storm Security Tools
PerJack is a TCP Session Hijack tool written in Perl. It does a man-in-the-middle attack, displays all active sessions and takes over the selected TCP session.
-
17:00
»
Packet Storm Security Recent Files
PerJack is a TCP Session Hijack tool written in Perl. It does a man-in-the-middle attack, displays all active sessions and takes over the selected TCP session.