vendor:
uzbl-core
by:
unknown
7.5
CVSS
HIGH
Arbitrary Command Injection
78
CWE
Product Name: uzbl-core
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2010-2071
CPE: a:uzbl_project:uzbl-core
Platforms Tested: Linux
2010
uzbl ‘uzbl-core’ Arbitrary Command Injection Vulnerability
uzbl 'uzbl-core' is prone to a vulnerability that lets attackers inject arbitrary commands because the application fails to adequately sanitize user-supplied input. This issue stems from an insecure default configuration setting. To exploit this issue, attackers must entice an unsuspecting user to click on a specially crafted URI with their middle mouse button. Exploiting this issue would permit remote attackers to inject and execute commands with the privileges of a user running the application.
Mitigation:
To mitigate this vulnerability, users are advised to update to the latest version of uzbl and avoid clicking on suspicious or untrusted links.