V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-12904
DEB
High

Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows rem…

CVSS
8.8
High
EPSS
0.06
p92
Published
2017-01-01
Updated
2017-01-01
Description

Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.

Tags · CWE
Pre-auth
CWE-943
CAPEC-676
Affected products
Debian_linux
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.064 · p92
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
newsbeuterTracked
newsbeuterTracked
newsbeuterTracked
newsbeuterTracked
newsbeuterTracked
newsbeuterTracked
newsbeuterTracked
newsbeuterTracked
debian_linux*Tracked
newsbeuter*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities