Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4hr-2hrx-m38c

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

EPSS

Процентиль: 86%
0.02889
Низкий

Связанные уязвимости

ubuntu
почти 19 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

redhat
около 19 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

nvd
почти 19 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

debian
почти 19 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell met ...

oracle-oval
больше 16 лет назад

ELSA-2009-1278: lftp security and bug fix update (LOW)

EPSS

Процентиль: 86%
0.02889
Низкий