gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gnatsweb | Yngve_svendsen | 2.7_beta (including) | 2.7_beta (including) |
Gnatsweb | Yngve_svendsen | 2.8.0 (including) | 2.8.0 (including) |
Gnatsweb | Yngve_svendsen | 2.8.1 (including) | 2.8.1 (including) |
Gnatsweb | Yngve_svendsen | 3.95-gnats_4 (including) | 3.95-gnats_4 (including) |