Total vulnerabilities in the database
The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."
Software | From | Fixed in |
---|---|---|
flashtux / weechat | 0.3.9 | 0.3.9.x |
flashtux / weechat | 0.3.1 | 0.3.1.x |
flashtux / weechat | 0.3.2 | 0.3.2.x |
flashtux / weechat | 0.3.9.1 | 0.3.9.1.x |
flashtux / weechat | 0.3.4 | 0.3.4.x |
flashtux / weechat | 0.3.0 | 0.3.0.x |
flashtux / weechat | 0.3.1.1 | 0.3.1.1.x |
flashtux / weechat | 0.3.7 | 0.3.7.x |
flashtux / weechat | 0.3.8 | 0.3.8.x |
flashtux / weechat | 0.3.6 | 0.3.6.x |
flashtux / weechat | 0.3.3 | 0.3.3.x |