Web Hack List

Top 10 winner

ShellShock

CVE - CVE-2014-6271

Shellshock: GNU Bash through 4.3 keeps executing text that trails a function definition stored in an environment variable. Any path that carries attacker-controlled data into the environment across a privilege boundary, such as Apache mod_cgi, OpenSSH ForceCommand or DHCP clients, therefore yields remote command execution.

Record

Document
CVE - CVE-2014-6271
Published by
cve.mitre.org
Format
Advisory
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of cve.mitre.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .