CVE-2018-16367
EUVD-2018-821302.09.2018, 22:29
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| qduoj | onlinejudge | 2.0 |
𝑥
= Vulnerable software versions