The get_url function in DODS_Dispatch.pm for the CGI_server in OPeNDAP 3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Server3 | Opendap | 3.2.10 (including) | 3.2.10 (including) |
Server3 | Opendap | 3.7.4 (including) | 3.7.4 (including) |