Mercurial Custom hg-ssh Wrapper Remote Code Execution
Posted by deepcore on April 27, 2017 – 7:49 am
This Metasploit module takes advantage of custom hg-ssh wrapper implementations that don’t adequately validate parameters passed to the hg binary, allowing users to trigger a Python Debugger session, which allows arbitrary Python code execution.
Post a reply
You must be logged in to post a comment.