Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6350

Опубликовано: 14 дек. 2007
Источник: nvd
CVSS2: 8.5
EPSS Низкий

Описание

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversion (SVN) repository with malicious hooks, then using svn to trigger execution of those hooks.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:scponly:scponly:*:*:*:*:*:*:*:*
Версия до 4.6 (включая)
cpe:2.3:a:scponly:scponly:4.2:*:*:*:*:*:*:*
cpe:2.3:a:scponly:scponly:4.3:*:*:*:*:*:*:*
cpe:2.3:a:scponly:scponly:4.4:*:*:*:*:*:*:*
cpe:2.3:a:scponly:scponly:4.5:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00837
Низкий

8.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 17 лет назад

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversion (SVN) repository with malicious hooks, then using svn to trigger execution of those hooks.

redhat
около 18 лет назад

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversion (SVN) repository with malicious hooks, then using svn to trigger execution of those hooks.

debian
больше 17 лет назад

scponly 4.6 and earlier allows remote authenticated users to bypass in ...

github
больше 3 лет назад

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversion (SVN) repository with malicious hooks, then using svn to trigger execution of those hooks.

fstec
больше 17 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 74%
0.00837
Низкий

8.5 High

CVSS2

Дефекты

CWE-264