6.8

CVE-2010-0394

PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NanosleepTrac-git Version <= 0.0.20080710
NanosleepTrac-git Version <= 0.0.20090320
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.37% 0.872
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567039
http://osvdb.org/62147
http://secunia.com/advisories/38325
Vendor Advisory
http://www.debian.org/security/2010/dsa-1990
http://www.securityfocus.com/bid/38076
https://exchange.xforce.ibmcloud.com/vulnerabilities/56105