config_converters.py in BSCW (Basic Support for Cooperative Work) 3.x and versions before 4.06 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name during filename conversion.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bscw | Fraunhofer_fit | 3.4 (including) | 3.4 (including) |
Bscw | Fraunhofer_fit | 4.0 (including) | 4.0 (including) |