CVE-2011-0633 describes a vulnerability in the Net::HTTPS module of libwww-perl (LWP) versions prior to 6.00, affecting products like WWW::Mechanize and LWP::UserAgent. This flaw allows remote attackers to spoof servers through man-in-the-middle (MITM) attacks due to insufficient SSL certificate validation, specifically when the If-SSL-Cert-Subject header is not set. The vulnerability carries a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and potential for partial integrity impact (data spoofing). There is no confidentiality or availability impact. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.01CPE matchmatch criteria | cpe:2.3:a:gisle_aas:libwww-perl:0.01:*:*:*:*:*:*:* | ||
0.02CPE matchmatch criteria | cpe:2.3:a:gisle_aas:libwww-perl:0.02:*:*:*:*:*:*:* | ||
0.03CPE matchmatch criteria | cpe:2.3:a:gisle_aas:libwww-perl:0.03:*:*:*:*:*:*:* | ||
0.04CPE matchmatch criteria | cpe:2.3:a:gisle_aas:libwww-perl:0.04:*:*:*:*:*:*:* | ||
5.00CPE matchmatch criteria | cpe:2.3:a:gisle_aas:libwww-perl:5.00:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.