CVE-2006-2548
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 13%
from disclosure to weapon0 days
Published on NVDMay 23
1st PoCMay 22
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/27902⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0567.htmlhttp://secunia.com/advisories/20208http://secunia.com/advisories/20238http://securityreason.com/securityalert/942https://exchange.xforce.ibmcloud.com/vulnerabilities/26568https://exchange.xforce.ibmcloud.com/vulnerabilities/26575http://sourceforge.net/project/shownotes.php?release_id=418189&group_id=148643http://www.osvdb.org/25690http://www.redteam-pentesting.de/advisories/rt-sa-2006-002.phphttp://www.redteam-pentesting.de/advisories/rt-sa-2006-003.phphttp://www.securityfocus.com/archive/1/434712/100/0/threadedhttp://www.securityfocus.com/bid/18068