Apache Subversion CVE-2013-2088 Command Injection Vulnerability
BID:60265
Info
Apache Subversion CVE-2013-2088 Command Injection Vulnerability
| Bugtraq ID: | 60265 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2088 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2013 12:00AM |
| Updated: | Sep 25 2013 12:15AM |
| Credit: | Daniel Shahaf, elego Software Solutions GmbH |
| Vulnerable: |
SuSE openSUSE 11.4 Gentoo Linux Apache Software Foundation Subversion 1.6.14 Apache Software Foundation Subversion 1.6.12 Apache Software Foundation Subversion 1.6.10 Apache Software Foundation Subversion 1.6.6 Apache Software Foundation Subversion 1.6.5 Apache Software Foundation Subversion 1.6.3 Apache Software Foundation Subversion 1.6.2 Apache Software Foundation Subversion 1.6.9 Apache Software Foundation Subversion 1.6.8 Apache Software Foundation Subversion 1.6.7 Apache Software Foundation Subversion 1.6.4 Apache Software Foundation Subversion 1.6.17 Apache Software Foundation Subversion 1.6.16 Apache Software Foundation Subversion 1.6.15 Apache Software Foundation Subversion 1.6.13 Apache Software Foundation Subversion 1.6.11 Apache Software Foundation Subversion 1.6.0 |
| Not Vulnerable: | |
Discussion
Apache Subversion CVE-2013-2088 Command Injection Vulnerability
Apache Subversion is prone to a command-injection vulnerability.
Exploiting this issue could allow an attacker to execute arbitrary commands in the context of the affected application.
Apache Subversion is prone to a command-injection vulnerability.
Exploiting this issue could allow an attacker to execute arbitrary commands in the context of the affected application.
Exploit / POC
Apache Subversion CVE-2013-2088 Command Injection Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Apache Subversion CVE-2013-2088 Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Subversion CVE-2013-2088 Command Injection Vulnerability
References:
References:
- Subversion Homepage (Subversion)