|
CVStrac contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due tot he filediff command not properly sanitizing input to the rcsinfo variable. With a specially crafted request, an attacker can execute arbitrary commands with the same permissions as the running server.
|