Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4hr-2hrx-m38c

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

EPSS

Процентиль: 84%
0.0243
Низкий

Связанные уязвимости

ubuntu
около 18 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

redhat
больше 18 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

nvd
около 18 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

debian
около 18 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell met ...

oracle-oval
почти 16 лет назад

ELSA-2009-1278: lftp security and bug fix update (LOW)

EPSS

Процентиль: 84%
0.0243
Низкий