VYPR

Mod Perl

by Apache

CVEs (2)

  • CVE-2009-0796Apr 7, 2009
    risk 0.08cvss epss 0.61

    Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

  • CVE-2007-1349Mar 30, 2007
    risk 0.01cvss epss 0.18

    PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.