Critical severity9.8NVD Advisory· Published Jul 23, 2020· Updated Jun 17, 2026
CVE-2020-15477
CVE-2020-15477
Description
The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters in a URI. The file nodejs/raspberryTortoise.js has no validation on the parameter incomingString before passing it to the child_process.exec function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:raspberrytorte:raspberrytortoise:*:*:*:*:*:*:*:*Range: <=2012-10-28
- RaspberryTortoise/RaspberryTortoisedescription
- Range: <=2012-10-28
Patches
Vulnerability mechanics
References
2- gist.github.com/PreethamBomma/e7b6d220790f95555dc2c5ac1d7d2f85nvdExploitThird Party Advisory
- github.com/raspberrytorte/tortoise/tree/master/nodejsnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.