vendor:
Links
by:
Unknown
8,8
CVSS
HIGH
Command Injection
78
CWE
Product Name: Links
Affected Version From: 1.00pre12
Affected Version To: 1.00pre12
Patch Exists: YES
Related CWE: CVE-2006-4010
CPE: cpe:a:links_developers:links
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 6.06 LTS
2006
Links smbclient command execution
Links web browser versions 1.00pre12 and earlier are vulnerable to command injection due to a flaw in the smb_func() function in smb.c. This flaw allows malicious web sites to execute smbclient commands on the victim's machine, allowing the attacker to read any file from the victim system (any file that the user running links has read access), or to upload any file to the victim system (any file that the user running links can create/overwrite).
Mitigation:
Upgrade to the latest version of Links web browser.