Taint Protection Bypass in Data::FormValidator Module

Taint Protection Bypass in Data::FormValidator Module

CVE-2011-2201 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.

Learn more about our Web Application Penetration Testing UK.