7.5
CVSSv2

CVE-2005-0015

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

diatheke.pl in Sword 1.5.7a allows remote malicious users to execute arbitrary commands via shell metacharacters in a URL.

Vulnerable Product Search on Vulmon Subscribe to Product

crosswire bible society sword 1.5.7a

Vendor Advisories

Ulf Härnhammar discovered that due to missing input sanitising in diatheke, a CGI script for making and browsing a bible website, it is possible to execute arbitrary commands via a specially crafted URL For the stable distribution (woody) this problem has been fixed in version 153-3woody2 For the unstable distribution (sid) this problem will b ...