It was discovered that cacti, a frontend to rrdtool, performs insufficient validation of data passed to the cmd script, which allows SQL injection and the execution of arbitrary shell commands.
Det har upptäckts att cacti, ett skal runt rrdtool, inte utför tillräcklig städning av data som sänts till skriptet cmd, vilket gjorde det möjligt att injicera SQL och exekvera godtyckliga skalkommandon.
Brian May discovered that pstotext, a utility to extract plain text from Postscript and PDF files, performs insufficient quoting of file names, which allows execution of arbitrary shell commands.
Brian May upptäckte att pstotext, ett verktyg som hämtar ut text ur Postscript- och PDF-filer, inte citerar filnamn tillräckligt, vilket gjorde det möjligt att exekvera godtyckliga skalkommandon.
This could allow the execution of arbitrary shell commands if the root user executed the command in a directory which other local users may write to.
Detta kunde göra det möjligt för exekvering av godtyckliga skalkommandon om rootanvändaren exekverade kommandot i en katalog där andra lokala användare kunde skriva.
"kcope" discovered that the wzdftpd FTP server lacks input sanitising for the SITE command, which may lead to the execution of arbitrary shell commands.
"kcope" upptäckte att ftp-servern wxdftpd inte städade indata till SITE-kommandot, vilket kunde leda till exekvering av godtyckliga skalkommandon.
Krzysztof Sieluzycki discovered that the notifier for removable devices in the KDE Plasma workspace performed insufficient sanitisation of FAT/VFAT volume labels, which could result in the execution of arbitrary shell commands if a removable device with a malformed disk label is mounted.
Sieluzycki upptäckte att notiferaren för borttagbara enheter i KDE plasma-arbetsytan utförde otillräcklig rengörning av FAT/VFAT-volymetiketter, vilket kunde resultera i exekvering av godtyckliga skalkommandon om en borttagbar enhet med en felaktigt formatterad disketikett monteras.
Charles Duffy discovered that the Commandline class in the utilities for the Plexus framework performs insufficient quoting of double-encoded strings, which could result in the execution of arbitrary shell commands.
Charles Duffy upptäckte att Commandline-klassen i verktygen för Plexus-ramverket utför otillräcklig citering av dubbelt kodade strängar, vilket kunde resultera i exekvering av godtyckliga skalkommandon.
Two vulnerabilities were discovered in the Open Ticket Request System which could result in information disclosure or the execution of arbitrary shell commands by logged-in agents.
Två sårbarheter upptäcktes i Open Ticket Request System vilket kunde resultera i utlämnande av information eller exekvering av godtyckliga skalkommandon av inloggade agenter.
Potentially sensitive or inappropriate content
Examples are used only to help you translate the word or expression searched in various contexts. They are not selected or validated by us and can contain inappropriate terms or ideas. Please report examples to be edited or not to be displayed. Potentially sensitive, inappropriate or colloquial translations are usually marked in red or in orange.