PT-2019-6893 · Fileutil · Fileutils
Larry W. Cashdollar
+1
·
Publicado
2019-02-15
·
Atualizado
2022-05-14
·
CVE-2013-2516
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Fileutils versions prior to 0.7.1
Description
The issue concerns a Command Injection vulnerability. It occurs when a user-supplied
url variable is passed to the shell, allowing for potential command injection.Recommendations
For versions prior to 0.7.1, update to version 0.7.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of user-supplied
url variables in the affected function until a patch is available. Avoid using the url variable in the affected API endpoint until the issue is resolved.Exploit
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fileutils