Skip to main content

Vendor/product archive

andy_armstrong / cgi.pm CVEs

Beta · best-effort

4 CVEs tagged to andy_armstrong / cgi.pm0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2012-5526

Published Nov 21, 2012

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into resp…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4411

Published Dec 6, 2010

Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1