CVE-2009-3233 describes a local command injection vulnerability in changetrack version 4.3. An attacker can execute arbitrary commands by embedding CRLF sequences and shell metacharacters within filenames in directories monitored by changetrack. This vulnerability carries a CVSS score of 7.2, indicating high severity with local access, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking widespread community discussion or media coverage, an exploit for local privilege escalation is publicly available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3CPE matchmatch criteria | cpe:2.3:a:cameron_morland:changetrack:4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.