CVE-2011-10007 describes an arbitrary code execution vulnerability in File::Find::Rule through version 0.34 for Perl. This flaw allows an attacker to execute arbitrary commands when the grep() function processes a specially crafted filename. The vulnerability arises because the two-argument form of open() is used, allowing an attacker-controlled filename to dictate the MODE parameter, effectively turning the filename into an executable command. This vulnerability carries a high severity CVSS score of 8.8, indicating a critical risk. It can be exploited remotely with low attack complexity, requiring user interaction (e.g., processing a malicious file) to achieve high impacts on confidentiality, integrity, and availability. The CWE-78 classification highlights the command injection nature of the flaw. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| RCLAMP | File::Find::Rule | >= 0, <= 0.34CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.