cbcvebase.
CVE-2011-2766
published 2011-09-23

CVE-2011-2766: The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later…

PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.24%
93.7th percentile
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlibfcgi-perl< libfcgi-perl 0.73-2 (bookworm)libfcgi-perl 0.73-2 (bookworm)
fast_cgi_projectfast_cgi0.70 – 0.73

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.