Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-2809
Description:The default configuration of the binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.
Test IDs: 1.3.6.1.4.1.25623.1.0.67947   1.3.6.1.4.1.25623.1.0.862669   1.3.6.1.4.1.25623.1.0.862332   1.3.6.1.4.1.25623.1.0.67950   1.3.6.1.4.1.25623.1.0.862335   1.3.6.1.4.1.25623.1.0.67917  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-2809
42297
http://www.securityfocus.com/bid/42297
[oss-security] 20100806 CVE request: uzbl before 2010.08.05: User-assisted execution of arbitrary commands caused by faulty default config
http://marc.info/?l=oss-security&m=128111493509265&w=2
[oss-security] 20100806 Re: CVE request: uzbl before 2010.08.05: User-assisted execution of arbitrary commands caused by faulty default config
http://marc.info/?l=oss-security&m=128111994317381&w=2
http://github.com/Dieterbe/uzbl/commit/9cc39cb5c9396be013b5dc2ba7e4b3eaa647e975
http://github.com/Dieterbe/uzbl/commit/9cc39cb5c9396be013b5dc2ba7e4b3eaa647e975
http://github.com/pawelz/uzbl/commit/342f292c27973c9df5f631a38bd12f14a9c5cdc2
http://github.com/pawelz/uzbl/commit/342f292c27973c9df5f631a38bd12f14a9c5cdc2
http://www.uzbl.org/bugs/index.php?do=details&task_id=240
http://www.uzbl.org/bugs/index.php?do=details&task_id=240
http://www.uzbl.org/news.php?id=29
http://www.uzbl.org/news.php?id=29
https://bugzilla.redhat.com/show_bug.cgi?id=621964
https://bugzilla.redhat.com/show_bug.cgi?id=621964
https://bugzilla.redhat.com/show_bug.cgi?id=621965
https://bugzilla.redhat.com/show_bug.cgi?id=621965
uzbl-atselecteduri-command-execution(61011)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61011




© 1998-2025 E-Soft Inc. All rights reserved.