Nom de la faiblesse | Source | |
---|---|---|
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |
Métriques | Score | Gravité | CVSS Vecteur | Source |
---|---|---|---|---|
V2 | 6 | AV:N/AC:M/Au:S/C:P/I:P/A:P | [email protected] |
Puppet>>Puppet >> Version From (including) 2.6.0 To (excluding) 2.6.15
Puppet>>Puppet >> Version From (including) 2.7.0 To (excluding) 2.7.13
Puppet>>Puppet_enterprise >> Version From (including) 1.2.0 To (excluding) 2.5.1
Puppet>>Puppet_enterprise >> Version 1.0
Puppet>>Puppet_enterprise >> Version 1.1
Fedoraproject>>Fedora >> Version 15
Fedoraproject>>Fedora >> Version 16
Fedoraproject>>Fedora >> Version 17
Debian>>Debian_linux >> Version 6.0
Debian>>Debian_linux >> Version 7.0
Canonical>>Ubuntu_linux >> Version 10.04
Canonical>>Ubuntu_linux >> Version 11.04
Canonical>>Ubuntu_linux >> Version 11.10