vendor:
FVWM
by:
Unknown
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: FVWM
Affected Version From: 2.14.17
Affected Version To: 2.5.2008
Patch Exists: NO
Related CWE: Unknown
CPE: a:fvwm_project:fvwm
Platforms Tested:
Unknown
Command Execution Vulnerability in FVWM
FVWM is prone to a command execution vulnerability that allows an attacker to execute arbitrary commands on a vulnerable system. The fvwm-menu-directory component does not properly sanitize user input, allowing a user with write permissions to a directory to execute arbitrary commands.
Mitigation:
It is recommended to sanitize user input properly in the fvwm-menu-directory component to prevent command execution vulnerabilities.