OS Command Injection in ohcount - CVE-2017-16926
Published: November 22, 2017 / Updated: August 8, 2020
ohcount
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for Ohcount processing) to execute arbitrary code as the user running Ohcount.