5.1
CVE-2006-2550
- EPSS 3.33%
- Veröffentlicht 23.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:25:18
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
perlpodder before 0.5 allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast, which are executed when saving the URL to a log file. NOTE: the wget vector is already covered by CVE-2006-2548.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Perlpodder ≫ Perlpodder Version <= 0.4
Perlpodder ≫ Perlpodder Version0.2
Perlpodder ≫ Perlpodder Version0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.33% | 0.87 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/20238
http://www.redteam-pentesting.de/advisories/rt-sa-2006-003.php
https://exchange.xforce.ibmcloud.com/vulnerabilities/26575
http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0570.html
http://www.osvdb.org/25708
http://www.securityfocus.com/archive/1/434711/100/0/threaded
http://www.securityfocus.com/bid/18067
http://www.vupen.com/english/advisories/2006/1906