Vulnerabilities (CVE)

Filtered by vendor Websvn Subscribe
Filtered by product Websvn
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-32305 1 Websvn 1 Websvn 2022-01-01 10.0 HIGH 9.8 CRITICAL
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
CVE-2011-2195 1 Websvn 1 Websvn 2021-10-29 9.3 HIGH 9.8 CRITICAL
A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.