cbcvebase.
CVE-2013-2088
published 2013-07-31

CVE-2013-2088: contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands…

PriorityP356high7.1CVSS 2.0
AVNACHAuSCCICAC
EXPLOIT
EPSS
31.47%
98.1th percentile
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
apachesubversion<= 1.6.21
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion>= 0 < 1.7.5-11.7.5-1
apachesubversion>= 0 < 1.7.5-11.7.5-1

CVSS provenance

nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
osv7.1HIGH
vendor_apache7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.