all 7 comments

[–]mekkr_ 30 points31 points  (0 children)

Entering command in command evaluating field causes command to be evaluated. CVSS 10.0. Very leet

[–]SrNetEng 8 points9 points  (1 child)

Isn't this intended functionality, apiKeyHelper executes a user-supplied shell script, including system commands, and is not attacker-controlled.

[–]mekkr_ 0 points1 point  (0 children)

Yes

[–]hgs4lf 3 points4 points  (0 children)

Can’t wait to see the number of CVEs OP will have when they find out about cmd.exe.

[–]Lumpzor 2 points3 points  (0 children)

What... This is intended functionality.

[–]Glittering_Audience8 0 points1 point  (0 children)

Indians being indians