Vulnerabilities > Ossp

DATE CVE VULNERABILITY TITLE RISK
2006-07-27 CVE-2006-3633 Improper Input Validation vulnerability in Ossp Shiela
OSSP shiela 1.1.5 and earlier allows remote authenticated users to execute arbitrary commands on the CVS server via shell metacharacters in a filename that is committed.
network
low complexity
ossp CWE-20
6.5
2002-08-12 CVE-2002-0658 Privilege Escalation vulnerability in MM Shared Memory Library Temporary File
OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
local
high complexity
ossp
6.2