vendor:
Cherokee
by:
9.8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: Cherokee
Affected Version From: 0.99.30
Affected Version To: 0.99.30
Patch Exists: YES
Related CWE:
CPE: a:cherokee:cherokee:0.99.30
Platforms Tested:
Cherokee Command Injection Vulnerability
Cherokee is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles. Attackers can exploit this issue to execute arbitrary commands in a terminal.
Mitigation:
Upgrade to Cherokee version 0.99.31 or later.