Loading HuntDB...

Shell command injection in https://partner.steamgames.com/apps/communityitems/ via file extension of item_image_small and item_image_large

Critical
V
Valve
Submitted None

Team Summary

Official summary from Valve

Shell injection was achieved on a publishing gateway through metacharacter injection in an item-upload path.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Command Injection - Generic