Remote Code Execution via Directory Traversal in Go Doc Dot Org (gddo)

Remote Code Execution via Directory Traversal in Go Doc Dot Org (gddo)

CVE-2018-12976 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.

Learn more about our Web Application Penetration Testing UK.