Sploitus

CVE-2017-9462

1 known exploit for CVE-2017-9462

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

Affected products
Alt Linux, Centos, Mercurial, Red Hat, Suse
Mercurial
< 4.1.3
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
21.7% (97th percentile)
Weakness
CWE-732
NVD status
Modified
Published
2017-06-06
CVE-2017-9462 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2017-9462

Proof-of-concept code and exploit modules indexed by Sploitus