CVE

Id
22782  
CVE No.
CVE-2006-6678  
Status
Candidate  
Description
The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.  
Phase
Assigned (20061220)  
Votes
None (candidate not yet proposed)  
Comments