Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded.
Module names starting with "::" could be passed to the load function to specify arbitrary module paths.
Attackers able to influence module names passed to load could use that bug to execute arbitrary code.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-07 12:16
Updated : 2026-07-07 17:16
NVD link : CVE-2011-10043
Mitre link : CVE-2011-10043
CVE.ORG link : CVE-2011-10043
JSON object : View
Products Affected
No product.
CWE
CWE-145
Improper Neutralization of Section Delimiters
