[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-7032 -- mr

ID: oval:org.secpod.oval:def:2000409Date: (C)2019-04-22   (M)2023-04-27
Class: VULNERABILITYFamily: unix




webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

Platform:
Debian 8.x
Debian 9.x
Product:
mr
Reference:
CVE-2018-7032
CVE    1
CVE-2018-7032
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:joeyh:mr

© SecPod Technologies