Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Search.Cpan Libwww-perl lwp-download输入验证漏洞
Vulnerability Description
Libwww 是一个高度模组化用户端的网页存取API ,用C语言写成,可在 Unix 和 Windows 上运行。 在libwww-perl 5.835之前的版本中的lwp-download不能拒绝以 .(点)字符开头文件名的下载,远程服务器可以借助(1)3xx重定向到含有伪造文件名的URL或者(2)类似伪造文件名一样的Content-Disposition头来创建或者覆盖文件,并且可能由于将此写入主目录dotfile中而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A