CVE-2020-10674 Information
Feb 14, 2021
cve
Description
PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands as demonstrated by use of system and 2-argument open.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://metacpan.org/source/JKAMPHAUS/PerlSpeak-2.01/Changes https://rt.cpan.org/Public/Bug/Display.html?id=132173
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: