perlpodder prior to 0.5 allows remote malicious users to execute arbitrary code via shell metacharacters in the URL of a podcast, which are executed when saving the URL to a log file. NOTE: the wget vector is already covered by CVE-2006-2548.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
perlpodder perlpodder 0.3 |
||
perlpodder perlpodder |
||
perlpodder perlpodder 0.2 |