Description
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
Affected products
- Apple / darwin_streaming_server4.1.2 – 4.1.2
- Apple / quicktime_streaming_server4.1.1 – 4.1.1