VYPR
Unrated severityNVD Advisory· Published Apr 30, 2007· Updated Apr 23, 2026

CVE-2007-2355

CVE-2007-2355

Description

The get_url function in DODS_Dispatch.pm for the CGI_server in OPeNDAP 3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

Affected products

2
  • Opendap/Server32 versions
    cpe:2.3:a:opendap:server3:3.2.10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:opendap:server3:3.2.10:*:*:*:*:*:*:*
    • cpe:2.3:a:opendap:server3:3.7.4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.