CVE-2013-2088

Apache Subversion < 1.6.21 - Improper Input Validation

Title source: rule
STIX 2.1

Description

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

Exploits (1)

exploitdb WORKING POC
by GlacierZ0ne · pythonremotelinux
https://www.exploit-db.com/exploits/40507

Scores

EPSS 0.0649
EPSS Percentile 91.1%

Details

CWE
CWE-20
Status published
Products (24)
apache/subversion 1.6.0
apache/subversion 1.6.1
apache/subversion 1.6.2
apache/subversion 1.6.3
apache/subversion 1.6.4
apache/subversion 1.6.5
apache/subversion 1.6.6
apache/subversion 1.6.7
apache/subversion 1.6.8
apache/subversion 1.6.9
... and 14 more
Published Jul 31, 2013
Tracked Since Feb 18, 2026