{"id":"GHSA-mhfv-8rc9-w38c","summary":"Arbitrary shell execution","details":"Uses of shell_exec() and exec() were not escaping filenames and configuration settings in most cases","modified":"2024-12-05T05:39:47.186469Z","published":"2022-03-26T00:06:00Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-03-26T00:06:00Z"},"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/squizlabs/php_codesniffer/2017-03-01.yaml"},{"type":"PACKAGE","url":"https://github.com/squizlabs/PHP_CodeSniffer"},{"type":"WEB","url":"https://github.com/squizlabs/PHP_CodeSniffer/releases/tag/2.8.1"}],"affected":[{"package":{"name":"squizlabs/php_codesniffer","ecosystem":"Packagist","purl":"pkg:composer/squizlabs/php_codesniffer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"2.8.1"}]}],"versions":["1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.5.0","1.5.0RC1","1.5.0RC2","1.5.0RC3","1.5.0RC4","1.5.1","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","2.0.0","2.0.0RC1","2.0.0RC2","2.0.0RC3","2.0.0RC4","2.0.0a1","2.0.0a2","2.1.0","2.2.0","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.5.0","2.5.1","2.6.0","2.6.1","2.6.2","2.7.0","2.7.1","2.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-mhfv-8rc9-w38c/GHSA-mhfv-8rc9-w38c.json"}}],"schema_version":"1.9.0"}