Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.
Link | Tags |
---|---|
http://sourceforge.net/mailarchive/message.php?msg_id=12539317 | mailing list patch |
http://secunia.com/advisories/16319 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/14463 | vdb entry |
http://sourceforge.net/mailarchive/forum.php?thread_id=7863293&forum_id=32318 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/21668 | vdb entry |
http://www.osvdb.org/18506 | vdb entry |