Release date: 2011-12-19
Updated on: 2011-12-20
Affected Systems:
Igor Yu. Vlasenko HTML: Template: Pro 0.9506
Unaffected system:
Igor Yu. Vlasenko HTML: Template: Pro 0.9507
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51117
Cve id: CVE-2011-4616
Perl is a high-level, general, literal, and dynamic programming language.
HTML: Template: Pro has a security vulnerability in implementation. Input passed through Template parameters are not properly filtered before being returned to users, attackers can execute arbitrary HTML and script code in the user's browser of the affected site.
<* Source: Shigeki Morimoto
Link: https://metacpan.org/diff/release/VIY/HTML-Template-Pro-0.9505/VIY/HTML-Template-Pro-0.9507
Http://cpansearch.perl.org/src/VIY/HTML-Template-Pro-0.9507/Changes
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Igor Yu. Vlasenko
-----------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://search.cpan.org /~ Viy/HTML-Template-Pro-0.9507/lib/HTML/Template/Pro. pm