CVE-2012-6329 is a critical remote command execution vulnerability affecting the Locale::Maketext implementation in Perl versions prior to 5.17.7, specifically impacting applications like TWiki and Foswiki. The flaw stems from improper handling of backslashes and fully qualified method names during compilation of bracket notation, allowing attackers to execute arbitrary commands via crafted translation strings. With a CVSS score of 7.5 (high severity) and an EPSS score indicating a high likelihood of exploitation, this vulnerability poses a significant risk of full compromise (confidentiality, integrity, and availability). Exploit code is publicly available through Metasploit modules for both Foswiki and TWiki, although there is no evidence of active exploitation in the wild or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.16.2CPE matchmatch criteria | cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:* | ||
5.10CPE matchmatch criteria | cpe:2.3:a:perl:perl:5.10:*:*:*:*:*:*:* | ||
5.10.0CPE matchmatch criteria | cpe:2.3:a:perl:perl:5.10.0:*:*:*:*:*:*:* | ||
5.10.0CPE matchmatch criteria | cpe:2.3:a:perl:perl:5.10.0:rc1:*:*:*:*:*:* | ||
5.10.0CPE matchmatch criteria | cpe:2.3:a:perl:perl:5.10.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.