Total vulnerabilities in the database
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
Software | From | Fixed in |
---|---|---|
university_of_washington / pine | 4.30 | 4.30.x |
university_of_washington / pine | 4.21 | 4.21.x |
university_of_washington / pine | 4.33 | 4.33.x |
university_of_washington / pine | 4.20 | 4.20.x |