Perl 的 YAML 模块在 1.30 版本之前存在一个安全漏洞,允许通过加载的 YAML 文档触发任意类的 DESTROY 方法。 当使用 标签时,YAML 解析器会将一个哈希结构绑定(bless)到指定名称的类中。文档中提供的数据将作为该对象的字段内容。当该对象离开其作用域时,Perl 会自动调用其 DESTROY 方法。 DESTROY 方法的具体行为取决于当前 Perl 进程中已加载的类。例如,在核心 Perl 模块 File::Temp::Dir 中,DESTROY 方法可能用于删除 YAML 文档中所
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 1.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet