cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-06-06 15:32
Updated : 2017-08-07 18:31
NVD link : CVE-2008-2575
Mitre link : CVE-2008-2575
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
jcoppens
- cbrpager