Security Advisories (1)
CVE-2012-6142 (2014-06-04)

HTML::EP::Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.

NAME

HTML::EP::Shop - An E-Commerce solution, based on HTML::EP

SYNOPSIS

DESCRIPTION

AUTHOR AND COPYRIGHT

This module is

Copyright (C) 1998    Jochen Wiedmann
                      Am Eisteich 9
                      72555 Metzingen
                      Germany

                      Phone: +49 7123 14887
                      Email: joe@ispsoft.de

All rights reserved.

You may distribute this module under the terms of either the GNU General Public License or the Artistic License, as specified in the Perl README file.

SEE ALSO

HTML::EP(3), HTML::EP::Session HTML::EP::Locale