Title : Scponly Multiple Command Handling Arbitrary Code Injection Vulnerabilities VUPEN ID : VUPEN/ADV-2007-4243 CVE ID : CVE-2007-6350 - CVE-2007-6415
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-18
Technical Description
A vulnerability has been identified in Scponly, which could be exploited by malicious users to bypass secuity restrictions. This issue is caused by a design error when executing user-supplied commands (e.g. "svn", "unison", "rsync", and "svnserve"), which could be exploited by attackers to execute arbitrary commands and compromise a vulnerable system.
Note: A second issue is present within the handling of certain options, which could be exploited to execute arbitrary commands.