E07-lkn01
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2007
Description
This strike exploits an arbitrary command execution vulnerability in CVSTrac.
The vulnerability is due to failure to properly sanitize user-supplied input to the rcsinfo parameter.
A remote attacker could execute arbitrary commands on the target system by sending shell metacharacters in a web request.