Exposure of Sensitive Information to an Unauthorized Actor
CVE-2013-7329
Summary
The CGI::Application module prior to 4.50_50 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive information (web queries and environment details) via vectors related to the "dump_html" function.
- LOW
- NETWORK
- NONE
- NONE
- PARTIAL
- NONE
CWE-200 - Information Exposure
An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.
Advisory Timeline
- Published