Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2010-0394
StatusCandidate
DescriptionPyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.
SeverityMedium
CVSS score6,8
CVSS vector(AV:N/AC:M/Au:N/C:P/I:P/A:P)
PhaseAssigned (10.02.2010)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0394
ReferencesBID : 38076
 CONFIRM : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=5...
 DEBIAN : DSA-1990
 OSVDB : 62147
 SECUNIA : 38325
 XF : tracgit-command-execution(56105)
SecurityVulns:Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server