RSS   Podatności dla 'Perlpodder'   RSS

2006-05-23
 
CVE-2006-2550

CWE-Other
 

 
perlpodder before 0.5 allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast, which are executed when saving the URL to a log file. NOTE: the wget vector is already covered by CVE-2006-2548.

 
 
CVE-2006-2548

CWE-94
 

 
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.

 


Copyright 2024, cxsecurity.com

 

Back to Top