CRITICAL
Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for Ohcount processing) to execute arbitrary code as the user running Ohcount
Published Nov 22, 2017
9.8
CRITICALCVSS 3.0
EPSS 5.58%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.