Prodder before 0.5, and perlpodder before 0.5, allows remote attackers...
Vulnerability Description
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2548
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26575
- http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0567.html
- http://www.securityfocus.com/bid/18068
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26568
- http://www.securityfocus.com/archive/1/434712/100/0/threaded
- http://www.vupen.com/english/advisories/2006/1905
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-002.php
- http://www.osvdb.org/25690
- http://secunia.com/advisories/20238
- http://www.redteam-pentesting.de/advisories/rt-sa-2006-003.php
- http://sourceforge.net/project/shownotes.php?release_id=418189&group_id=148643
- http://secunia.com/advisories/20208
- http://securityreason.com/securityalert/942
Affected Vendor
perlpodder
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.