CVE-2013-7050
Published Dec 13, 2013
Last updated a year ago
Overview
- Description
- The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-94
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C55DCA95-69BB-4155-B0BA-012CB0453A15", "versionEndIncluding": "2.13.7" }, { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:2.13.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E1C3E21-A06A-4922-834A-0D28F8722B4F" }, { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:2.13.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6608A1F3-5266-45EC-9BAD-ECCF67C3BDC4" }, { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:2.13.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "32157B0A-85E8-4A21-86EA-1144309C2AD4" }, { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:2.13.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "674AC75A-4934-45FD-8198-0522CA36C136" }, { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:2.13.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0434ED70-5BD5-4862-ACB9-48235D5A8D4C" }, { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:2.13.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "655BFC26-CF34-4D23-91A1-7EC0F6EA7403" }, { "criteria": "cpe:2.3:a:devscripts_devel_team:devscripts:2.13.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A21D910-5467-4B69-ACD8-4CCC48806945" } ], "operator": "OR" } ] } ]