Arbitrary Command Execution via File Preview in Sketch 0.6.12 and Earlier

Arbitrary Command Execution via File Preview in Sketch 0.6.12 and Earlier

CVE-2002-2047 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file.

Learn more about our Web Application Penetration Testing UK.