6.8
CVE-2010-0394
- EPSS 3.37%
- Veröffentlicht 10.02.2010 02:30:00
- Zuletzt bearbeitet 16.06.2026 23:16:04
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.37% | 0.872 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567039
http://osvdb.org/62147
http://secunia.com/advisories/38325
http://www.debian.org/security/2010/dsa-1990
http://www.securityfocus.com/bid/38076
https://exchange.xforce.ibmcloud.com/vulnerabilities/56105