HIGH
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget
Published May 23, 2006
7.5
HIGHCVSS 2.0
EPSS 13.28%
Description
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
Affected products
No data.
OR
- ≤ 0.4
- 0.2
- 0.3
- ≤ 0.4
- 0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0567.html mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/20208 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/20238 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/942 third-party-advisoryx_refsource_SREASON
- http://sourceforge.net/project/shownotes.php?release_id=418189&group_id=148643 x_refsource_CONFIRMPatch
- http://www.osvdb.org/25690 vdb-entryx_refsource_OSVDB
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-002.php x_refsource_MISCExploitPatchVendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-003.php x_refsource_MISCExploitPatchVendor Advisory
- http://www.securityfocus.com/archive/1/434712/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/18068 vdb-entryx_refsource_BIDExploitPatch
- http://www.vupen.com/english/advisories/2006/1905 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26568 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26575 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 23, 2006
Updated Aug 7, 2024
Reserved May 22, 2006
Link CVE-2006-2548
CISA Vulnrichment
Updated n/a