Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A properly crafted filename would allow for arbitrary code execution when using the –filter=gitmodified command line option.
A properly crafted filename would allow for arbitrary code execution when using the –filter=gitmodified command line option.
Uses of shell_exec() and exec() were not escaping filenames and configuration settings in most cases.
Arbitrary shell execution in php_codesniffer.
A properly crafted filename would allow for arbitrary code execution when using the –filter=gitmodified command line option
This release contains a fix for a security advisory related to the improper handling of shell commands. Uses of shell_exec() and exec() were not escaping filenames and configuration settings in most cases A properly crafted filename or configuration option would allow for arbitrary code execution when using some features.
Arbitrary shell execution in php_codesniffer.