Files
CVEs-PoC/2017/CVE-2017-12836.md
2025-09-29 21:09:30 +02:00

690 B

CVE-2017-12836

Description

CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar."

POC

Reference

No PoCs from references.

Github