Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-2348

Опубликовано: 27 апр. 2007
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:alexander_v._lukyanov:lftp:*:*:*:*:*:*:*:*
Версия до 3.5.8 (включая)

EPSS

Процентиль: 84%
0.0243
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 18 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

redhat
больше 18 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

debian
около 18 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell met ...

github
около 3 лет назад

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

oracle-oval
почти 16 лет назад

ELSA-2009-1278: lftp security and bug fix update (LOW)

EPSS

Процентиль: 84%
0.0243
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other