Secunia
|
|

CVE Reference: CVE-2007-6350 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2007-6350 |
|
|
Description: scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversion (SVN) repository with malicious hooks, then using svn to trigger execution of those hooks. |
|
|
CVE Status: Candidate |
|
|
References: ST 1019103 SAID Secunia Advisory: SA28123 Secunia Advisory: SA28538 Secunia Advisory: SA28944 Secunia Advisory: SA28981 OSVDB 44137 GENTOO http://security.gentoo.org/glsa/glsa-200802-06.xml FEDORA DEBIAN http://www.debian.org/security/2008/dsa-1473 CONFIRM http://bugs.gentoo.org/show_bug.cgi?id=201726 http://scponly.cvs.sourceforge.net/scponly/scponly/SECURITY?view=markup http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=437148 BID 26900 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |