SOAP::Lite Remote Arbitrary Command...

- AV AC AU C I A
发布: 2001-12-28
修订: 2025-04-13

SOAP::Lite is a collection of Perl modules providing an implementation of the Simple Object Access Protocol (SOAP). It includes support for both client and server programming. A vulnerability has been reported in some versions of SOAP::Lite. It is possible to execute arbitrary Perl functions as the server process, including attacker supplied parameters. This may happen when an attacker provides a fully qualified method to the SOAP call, including Perl package names. Usage of functions such as POSIX::system() may then result in arbitrary shell commands being executed by the server process, and lead to local access to the vulnerable system.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息