Perl 的 Punk 模块在 0.18 版本之前存在会话Cookie伪造漏洞。当会话未设置秘密密钥(secret)时,由于默认使用了空的HMAC密钥,攻击者可伪造会话Cookie。 具体而言, 关键字会将其配置选项直接应用于应用程序,且不会强制要求提供秘密密钥,也不会因缺少密钥而发出警告或拒绝启动。在读取和写入Cookie时,该密钥默认会被设置为空字符串。因此,如果在会话声明中未指定secret选项,或将其设为未定义或空值,系统实际上会使用一个零长度的 HMAC-SHA256 密钥进行签名和验证。 一旦攻击者了解
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 0.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet