Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-2809

Опубликовано: 19 авг. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The default configuration of the binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:uzbl:uzbl:*:*:*:*:*:*:*:*
Версия до 2010.04.03 (включая)
cpe:2.3:a:uzbl:uzbl:2009.12.22:*:*:*:*:*:*:*
cpe:2.3:a:uzbl:uzbl:2010.01.04:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05768
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 15 лет назад

The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.

debian
больше 15 лет назад

The default configuration of the <Button2> binding in Uzbl before 2010 ...

github
больше 3 лет назад

The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.

EPSS

Процентиль: 90%
0.05768
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94