The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/2912 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/192711 | mailing list patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6743 | vdb entry |