Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2x8-qgjm-w8gp

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.

Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.

EPSS

Процентиль: 80%
0.02005
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.

CVSS3: 8.8
nvd
почти 9 лет назад

Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.

CVSS3: 8.8
debian
почти 9 лет назад

Phabricator before 2017-11-10 does not block the --config and --debugg ...

EPSS

Процентиль: 80%
0.02005
Низкий

8.8 High

CVSS3