CVE-2008-6793

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
07/05/2009
Last modified:
09/04/2025

Description

The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters after an arg1= sequence in a filename within a forensic image.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dflabs:ptk:0.1:*:*:*:*:*:*:*
cpe:2.3:a:dflabs:ptk:0.2:*:*:*:*:*:*:*
cpe:2.3:a:dflabs:ptk:1.0:*:*:*:*:*:*:*