10
CVSSv2

CVE-2015-0850

Published: 02/06/2015 Updated: 03/06/2015
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Git plugin for FusionForge prior to 6.0rc4 allows remote malicious users to execute arbitrary code via an unspecified parameter when creating a secondary Git repository.

Vulnerable Product Search on Vulmon Subscribe to Product

fusionforge fusionforge

Vendor Advisories

Ansgar Burchardt discovered that the Git plugin for FusionForge, a web-based project-management and collaboration software, does not sufficiently validate user provided input as parameter to the method to create secondary Git repositories A remote attacker can use this flaw to execute arbitrary code as root via a specially crafted URL For the sta ...