peter bassill · operator
$ cve CVE-2011-2767 JSON

CVE-2011-2767

9.8
CRITICAL · CVSS 3.0 · EPSS 8.9% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.95% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2018-08-26
Last modified2026-06-16

Affected (7)

VendorProduct
apachemod perl
canonicalubuntu linux
debiandebian linux
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD