← Back

CVE-2011-1589

nvd nist
Published: Apr 29, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI.

Affected (82)

1 product
Mojolicious
Configuration A
82 vulnerable
Vulnerable SoftwareAffected Versions
Mojolicious
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.8.1
Version 0.8.2
Version 0.8.3
Version 0.8.4
Version 0.8.5
Version 0.8006
Version 0.8007
Version 0.8008
Version 0.8009
Version 0.8
Version 0.9001
Version 0.9002
Version 0.991231
Version 0.991232
Version 0.991233
Version 0.991234
Version 0.991235
Version 0.991236
Version 0.991237
Version 0.991238
Version 0.991239
Version 0.991240
Version 0.991241
Version 0.991242
Version 0.991243
Version 0.991244
Version 0.991245
Version 0.991246
Version 0.991250
Version 0.991251
Version 0.999901
Version 0.999902
Version 0.999903
Version 0.999904
Version 0.999905
Version 0.999906
Version 0.999907
Version 0.999908
Version 0.999909
Version 0.999910
Version 0.999911
Version 0.999912
Version 0.999913
Version 0.999914
Version 0.999920
Version 0.999921
Version 0.999922
Version 0.999923
Version 0.999924
Version 0.999925
Version 0.999926
Version 0.999927
Version 0.999928
Version 0.999929
Version 0.999930
Version 0.999931
Version 0.999932
Version 0.999933
Version 0.999934
Version 0.999935
Version 0.999936
Version 0.999937
Version 0.999938
Version 0.999939
Version 0.999940
Version 0.999941
Version 0.999950
Version 0.9
Version 1.01
Version 1.0
Version 1.11
Version 1.12
Version 1.13
Version 1.14
Version 1.15
Version 1.1

References (40)

Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.