The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.
References
Configurations
History
No history.
Information
Published : 2012-08-31 18:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-4245
Mitre link : CVE-2012-4245
CVE.ORG link : CVE-2012-4245
JSON object : View
Products Affected
gimp
- gimp
CWE
CWE-862
Missing Authorization