CVE

Id
59384  
CVE No.
CVE-2012-6141  
Status
Candidate  
Description
The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request to (1) App::Session::Cookie or (2) App::Session::HTMLHidden, which is not properly handled when it is deserialized.  
Phase
Assigned (20121206)  
Votes
None (candidate not yet proposed)  
Comments