CVE detail
CVE-2011-2195 — CVE-2011-2195
Published 2021-10-26 · Modified 2026-06-16 · Vendor websvn · Product websvn · Source nvd
CRITICAL
severity
CVSS-derived band
0.0258
EPSS probability
exploitation probability, 30d
84.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References