CVE detail
CVE-2007-1349 — CVE-2007-1349
Published 2007-03-30 · Modified 2026-06-16 · Vendor apache · Product mod_perl · Source nvd
UNKNOWN
severity
CVSS-derived band
0.1011
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References