The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.
References
Configurations
History
No history.
Information
Published : 2011-09-23 10:55
Updated : 2025-04-11 00:51
NVD link : CVE-2011-2766
Mitre link : CVE-2011-2766
CVE.ORG link : CVE-2011-2766
JSON object : View
Products Affected
debian
- debian_linux
fast_cgi_project
- fast_cgi
CWE
CWE-287
Improper Authentication