CVE-2006-2548

UnknownEPSS 8.50%

Last modified

CVE-2006-2548 is a vulnerability of currently unknown severity. Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.. EPSS estimates a 8.50% chance of exploitation in the next 30 days.

Description

Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.

Metrics

EPSS Probability
8.50%

94.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PerlpodderPerlpodder<= 0.4
PerlpodderPerlpodder0.2
PerlpodderPerlpodder0.3
ProdderProdder<= 0.4
ProdderProdder0.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-2548?
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
How severe is CVE-2006-2548?
Severity scoring for CVE-2006-2548 is pending analysis. The EPSS model estimates a 8.50% probability of exploitation in the next 30 days.
How do I fix CVE-2006-2548?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-2548?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST