viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.
Link | Tags |
---|---|
http://secunia.com/advisories/13845 | patch vendor advisory third party advisory |
http://www.securityfocus.com/bid/13716 | patch vdb entry exploit |
http://marc.info/?l=bugtraq&m=111695779919830&w=2 | mailing list |