Description
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Exploits (1)
References (6)
Scores
EPSS
0.0649
EPSS Percentile
91.1%
Details
CWE
CWE-20
Status
published
Products (24)
apache/subversion
1.6.0
apache/subversion
1.6.1
apache/subversion
1.6.2
apache/subversion
1.6.3
apache/subversion
1.6.4
apache/subversion
1.6.5
apache/subversion
1.6.6
apache/subversion
1.6.7
apache/subversion
1.6.8
apache/subversion
1.6.9
... and 14 more
Published
Jul 31, 2013
Tracked Since
Feb 18, 2026