CVE-2013-4663: Command Injection
githttpcontroller.rb in the redminegithosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the getinforefs function or (2) the reqfile argument to the fileexists function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4663?
CVE-2013-4663 has a high severity rating due to the ability for remote attackers to execute arbitrary commands.
How do I fix CVE-2013-4663?
To fix CVE-2013-4663, update the redmine_git_hosting plugin to the latest version that addresses this vulnerability.
What software is affected by CVE-2013-4663?
CVE-2013-4663 affects the redmine_git_hosting plugin for Redmine.
What types of attacks can exploit CVE-2013-4663?
CVEs within this vulnerability can allow remote attackers to conduct command injection attacks due to improper handling of user input.
What are the consequences of CVE-2013-4663 exploitation?
Exploitation of CVE-2013-4663 can lead to remote execution of arbitrary commands on the server, potentially compromising the entire system.