Web Hack List

Top 10 winner

ShellShock

Shellshock: GNU Bash through 4.3 keeps executing text that trails a function definition stored in an environment variable. Any path that carries attacker-controlled data into the environment across a privilege boundary, such as Apache mod_cgi, OpenSSH ForceCommand or DHCP clients, therefore yields remote command execution.

Record

Published by
cve.mitre.org
Format
Advisory

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of cve.mitre.org, first published at the original source. Preserved copies are kept so the citation survives its host.