gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6753 | vdb entry |
http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html | patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2001-06/0365.html | mailing list patch vendor advisory |