Back to search
CVE-2006-6678
Published: Dec 21, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-1251
vendor-advisory
x_refsource_DEBIAN
22158
vdb-entry
x_refsource_BID
ADV-2006-5092
vdb-entry
x_refsource_VUPEN
23822
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now