CVSWeb insecure perl...

- AV AC AU C I A
发布: 2000-07-12
修订: 2025-04-13

Cvsweb 1.80 makes an insecure call to the perl OPEN function, providing attackers with write access to a cvs repository the ability to execute arbitrary commands on the host machine. The code that is being exploited here is the following: open($fh, "rlog '$filenames' 2>/dev/null |")

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息