CVE-2006-2548
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 13.28% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- perlpodder/perlpodder · prodder/prodder
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0567.html
- http://secunia.com/advisories/20208Patch, Vendor Advisory
- http://secunia.com/advisories/20238
- http://securityreason.com/securityalert/942
- http://sourceforge.net/project/shownotes.php?release_id=418189&group_id=148643Patch
- http://www.osvdb.org/25690
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-002.phpExploit, Patch, Vendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-003.phpExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/434712/100/0/threaded
- http://www.securityfocus.com/bid/18068Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1905Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26568
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26575
- http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0567.html
- http://secunia.com/advisories/20208Patch, Vendor Advisory
- http://secunia.com/advisories/20238
- http://securityreason.com/securityalert/942
- http://sourceforge.net/project/shownotes.php?release_id=418189&group_id=148643Patch
- http://www.osvdb.org/25690
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-002.phpExploit, Patch, Vendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-003.phpExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/434712/100/0/threaded
- http://www.securityfocus.com/bid/18068Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1905Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26568
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26575
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.