Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29216
HistoryFeb 03, 2021 - 4:10 a.m.

OS Command Injection

2021-02-0304:10:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
mechanize kernel.open exploitation untrusted input vulnerability

EPSS

0.003

Percentile

69.7%

mechanize is vulnerable to OS command injection. The Kernel.open method could be used to inject and execute arbitrary OS commands invoked through several class methods. Exploitation is possible when untrusted input is used as a local filename and is passed to the affected functions.