Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CVSTrac filediff Remote Command Execution Vulnerability

CVSTrac is affected by a remote command execution vulnerability in the 'filediff' functionality. This issue is due to an input validation error that allows for the appending of shell commands.

An attacker could leverage this issue to execute arbitrary shell commands on a vulnerable computer with the privileges of the web server process.







 

Privacy Statement
Copyright 2009, SecurityFocus