Arbitrary Command Execution in Vim 6.3

Arbitrary Command Execution in Vim 6.3

CVE-2005-2368 · HIGH Severity

AV:N/AC:M/AU:N/C:C/I:C/A:C

vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.

Learn more about our External Network Penetration Testing.