The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cvsweb | Cvsweb_developer | 1.80 (including) | 1.80 (including) |