acccheck.pl in acccheck 0.2.1 allows Command Injection via shell metacharacters in a username or password file, as demonstrated by injection into an smbclient command line.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://b3n7s.github.io/acccheck-command-injection.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-06-13T11:00:00
Updated: 2024-08-05T08:30:59.653Z
Reserved: 2018-06-13T00:00:00
Link: CVE-2018-12268
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-13T11:29:00.450
Modified: 2024-11-21T03:44:53.660
Link: CVE-2018-12268
Redhat
No data.