Security Advisory
CVE-2012-4245
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.