GHSA-jccv-3h4x-35mv
Dashboard / Vulnerabilities / GHSA-jccv-3h4x-35mv
Summary: Codiad Vulnerable to Shell Command Injection
Details: components/filemanager/class.filemanager.php in Codiad before 2.8.3 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by `search_file_type`.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-11366, https://github.com/Codiad/Codiad/issues/1011, https://github.com/Codiad/Codiad/pull/1013, https://github.com/Codiad/Codiad/pull/1013/commits/b3645b4c6718cef6de7003f41aafe7bfcc0395d1, https://github.com/Codiad/Codiad/commit/ca5089eeba42d16ce3a7f86be628ac7750780111, https://github.com/Codiad/Codiad, http://www.jianshu.com/p/41ac7ac2a7af
Affected packages
Package
Name: codiad/codiad
Purl: pkg:composer/codiad/codiad
Affected ranges
Type: ECOSYSTEM
Events:
