Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4101

Опубликовано: 18 сент. 2008
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия до 7.2 (включая)
cpe:2.3:a:vim:vim:3.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:4.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.1:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.2:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.3:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.4:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.5:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.6:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.7:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:5.8:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.1:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.2:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.3:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:6.4:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.0:*:*:*:*:*:*:*
cpe:2.3:a:vim:vim:7.1:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.10725
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 17 лет назад

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

redhat
около 17 лет назад

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

debian
почти 17 лет назад

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters ...

github
больше 3 лет назад

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

oracle-oval
почти 17 лет назад

ELSA-2008-0580: vim security update (MODERATE)

EPSS

Процентиль: 93%
0.10725
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20