csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Csvform | Mutasem_abudahab | 0.1 (including) | 0.1 (including) |
| Csvform_plus | Mutasem_abudahab | 1.0 (including) | 1.0 (including) |
References