Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-2968Mozilla Firefox vulnerability

8 documents7 sources
Severity
7.5HIGHNVD
EPSS
45.9%
top 2.36%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 20
Latest updateMay 3

Description

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDmozilla/firefox1.0.6
NVDmozilla/mozilla1.7.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-56cv-7m3h-rjxp: Firefox 12022-05-03
CVEList
CVE-2005-2968: Firefox 12005-09-20

💥Exploits & PoCs

1
Exploit-DB
Mozilla Browser/Firefox - Arbitrary Command Execution2005-09-20

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2005-10-11
Ubuntu
Mozilla and Firefox vulnerabilities2005-09-23
Red Hat
security flaw2005-09-06

💬Community

1
Bugzilla
CVE-2005-2968 security flaw2018-08-16