CVE-2006-3633
Published Jul 27, 2006OSSP shiela 1.1.5 and earlier allows remote authenticated users to execute arbitrary commands on the CVS server via shell metacharacters in a filename that is committed.
Vendor archive
2 CVEs tagged to vendor ossp — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
OSSP shiela 1.1.5 and earlier allows remote authenticated users to execute arbitrary commands on the CVS server via shell metacharacters in a filename that is committed.
OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.