Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.
Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command.
The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.
Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command.
The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
This application has not been updated since 2007 and appears to have been abandoned. Use other solutions.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection. | |
| Title | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE | |
| Weaknesses | CWE-78 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-13T22:24:42.216Z
Reserved: 2026-05-13T20:31:51.641Z
Link: CVE-2026-8500
No data.
Status : Received
Published: 2026-05-13T23:16:43.237
Modified: 2026-05-13T23:16:43.237
Link: CVE-2026-8500
No data.
OpenCVE Enrichment
Updated: 2026-05-13T23:30:06Z
Weaknesses