The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tattle | C.j._steele | * | * |