Security Advisories (4)
CPANSA-libwww-perl-2017-01 (2017-11-06)

LWP::Protocol::file can open existent file from file:// scheme. However, current version of LWP uses open FILEHANDLE,EXPR and it has ability to execute arbitrary command

CVE-2011-0633 (2011-01-20)

The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated.

CVE-2010-2253 (2010-07-06)

lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

CPANSA-libwww-perl-2001-01 (2001-03-14)

If LWP::UserAgent::env_proxy is called in a CGI environment, the case-insensitivity when looking for "http_proxy" permits "HTTP_PROXY" to be found, but this can be trivially set by the web client using the "Proxy:" header.

Documentation

Simple mirror utility for WWW

Modules

Interface to Adobe Font Metrics files
Class for objects that represent HTML elements
Expand HTML entites in a string
Format HTML as postscript
Format HTML as text
Base class for HTML formatters
Parse HTML text
Class encapsulating HTTP Message headers
Class encapsulating HTTP messages
Class encapsulating HTTP Requests
Class encapsulating HTTP Responses
HTTP Status code processing
LWP
Library for WWW access in Perl
debug routines
Low level I/O capability
guess media type for a file or an URL.
Member access mixin class
Virtual base class for LWP protocols
TCP/IP socket interface
A WWW UserAgent class
Encode string using base64 encoding
Encode string using quoted-printable encoding
Parse mailcap files
Escape unsafe characters
Uniform Resource Locators (absolute and relative)

Provides

in lib/Font/Courier.pm
in lib/Font/CourierBold.pm
in lib/Font/CourierBoldOblique.pm
in lib/Font/CourierOblique.pm
in lib/Font/Helvetica.pm
in lib/Font/HelveticaBold.pm
in lib/Font/HelveticaBoldOblique.pm
in lib/Font/HelveticaOblique.pm
in lib/Font/TimesBold.pm
in lib/Font/TimesBoldItalic.pm
in lib/Font/TimesItalic.pm
in lib/Font/TimesRoman.pm
in lib/HTML/AsSubs.pm
in lib/HTTP/Date.pm
in lib/LWP/TkIO.pm
in lib/LWP/Protocol/file.pm
in lib/LWP/Protocol/ftp.pm
in lib/LWP/Protocol/gopher.pm
in lib/LWP/Protocol/http.pm
in lib/LWP/Protocol/mailto.pm
in lib/LWP/Simple.pm
in lib/URI/URL.pm
in lib/URI/URL/file.pm
in lib/URI/URL/finger.pm
in lib/URI/URL/ftp.pm
in lib/URI/URL/gopher.pm
in lib/URI/URL.pm
in lib/URI/URL/https.pm
in lib/URI/URL/mailto.pm
in lib/URI/URL/news.pm
in lib/URI/URL/nntp.pm
in lib/URI/URL/prospero.pm
in lib/URI/URL/rlogin.pm
in lib/URI/URL/telnet.pm
in lib/URI/URL/tn3270.pm
in lib/URI/URL/wais.pm
in lib/URI/URL/webster.pm
in lib/URI/URL/whois.pm