CVSTrac FileDiff v2 Parameter Command Execution

Strike ID:
E07-lkn01
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2007

Description

This strike exploits an arbitrary command execution vulnerability in CVSTrac. The vulnerability is due to failure to properly sanitize user-supplied input to the rcsinfo parameter. A remote attacker could execute arbitrary commands on the target system by sending shell metacharacters in a web request.

CVE

Bid