scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversion (SVN) repository with malicious hooks, then using svn to trigger execution of those hooks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-12-14T20:00:00

Updated: 2024-08-07T16:02:36.466Z

Reserved: 2007-12-14T00:00:00

Link: CVE-2007-6350

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2007-12-14T20:46:00.000

Modified: 2011-08-08T04:00:00.000

Link: CVE-2007-6350

cve-icon Redhat

Severity :

Publid Date: 2007-08-10T00:00:00Z

Links: CVE-2007-6350 - Bugzilla