Description
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
Affected products
- university_of_washington / pine4.20 – 4.20
- university_of_washington / pine4.21 – 4.21
- university_of_washington / pine4.30 – 4.30
- university_of_washington / pine4.33 – 4.33