CVE-2021-36770

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.


We have discovered 36,191 live websites that are affected by CVE-2021-36770.

Test my site




Affected Software

Product  Perl
Category Programming Languages
Vulnerable Domains36,191 live websites (93.70% of Perl install base)
Vulnerable Versions
  • from 0 through 5.34
Vulnerable Versions Count56 versions ( 82.35% of all versions)



Details

  • Published - Aug 12, 2021
  • Updated - Aug 4, 2024

CVE-2021-36770 usage by Country

United States10,031 websites



Russia3,811 websites
France2,747 websites
Germany2,532 websites
Chile1,903 websites
Finland1,420 websites
Japan1,391 websites
China1,098 websites
Czech Republic1,059 websites

CVE-2021-36770 usage by TLD

.com13,448 websites
.ru3,161 websites
.org2,282 websites
.net1,977 websites
.de1,848 websites
.fi1,054 websites
.cz744 websites
.edu716 websites
.fr543 websites
.at519 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-36770

Top websites that are affected by CVE-2021-36770. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.********.***.uk GB*,***
***.***.org United States*,***
******.com United States*,***
**********.org United States*,***
*****.com United States*,***
**********.*****.de Germany*,***
*****.********.edu United States*,***
********************.org United States**,***
****.***.edu GB**,***
*********.com United States**,***
See full domain list

FAQ

A total of 36,191 websites have been identified as vulnerable to CVE-2021-36770, discovered through global website indexing conducted by WebTechSurvey.
Perl is susceptible to CVE-2021-36770 vulnerability.
Perl versions before, and including, 5.34 are vulnerable to CVE-2021-36770.