CVE-2010-0934: OS Command Injection
The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system commands by using a "p4 client" command in conjunction with the form-in trigger script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0934?
CVE-2010-0934 is considered to have a high severity due to its ability to allow remote authenticated users to execute arbitrary operating-system commands.
How do I fix CVE-2010-0934?
To fix CVE-2010-0934, upgrade to a more secure version of Perforce Server that mitigates this vulnerability.
Who is affected by CVE-2010-0934?
CVE-2010-0934 affects remote authenticated users with super privileges in Perforce Server 2008.1.
What are the implications of exploiting CVE-2010-0934?
Exploiting CVE-2010-0934 could allow an attacker to execute arbitrary commands on the host system, leading to potential data breaches or service disruptions.
Is there a workaround for CVE-2010-0934?
A possible workaround for CVE-2010-0934 includes restricting the use of the 'p4 client' command and limiting super privileges among users.