gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gnatsweb | Yngve_svendsen | 2.7_beta | 2.7_beta |
Gnatsweb | Yngve_svendsen | 2.8.0 | 2.8.0 |
Gnatsweb | Yngve_svendsen | 2.8.1 | 2.8.1 |
Gnatsweb | Yngve_svendsen | 3.95 | 3.95 |