Debian Security Advisory 1297-1 – Bernhard R. Link discovered that the CVS browsing interface of Gforge, a collaborative development tool, performs insufficient escaping of URLs, which allows the execution of arbitrary shell commands with the privileges of the www-data user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56942/dsa-1297-1.txt
Source: https://packetstormsecurity.com/files/56942/Debian-Linux-Security-Advisory-1297-1.html

