CVE-2008-2575
published 2008-06-06CVE-2008-2575: cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka…
PriorityP334medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.65%
84.1th percentile
cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jcoppens | cbrpager | < 0.9.17 | 0.9.17 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cbrpager: Command executions via improper shell escaping
vendor_redhat·2008-05-23·CVSS 6.8
CVE-2008-2575 [MEDIUM] cbrpager: Command executions via improper shell escaping
cbrpager: Command executions via improper shell escaping
cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
GHSA
GHSA-7w42-h9j5-82q5: cbrPager before 0
ghsa_unreviewed·2022-05-01
CVE-2008-2575 [MEDIUM] CWE-78 GHSA-7w42-h9j5-82q5: cbrPager before 0
cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
No detection rules found.
No public exploits indexed.
http://cvs.fedoraproject.org/viewcvs/rpms/cbrpager/devel/cbrpager-0.9.16-filen-shell-escaping.patch?rev=1.2http://secunia.com/advisories/30417http://secunia.com/advisories/30438http://secunia.com/advisories/30701http://security.gentoo.org/glsa/glsa-200806-05.xmlhttp://sourceforge.net/forum/forum.php?forum_id=827120http://sourceforge.net/project/shownotes.php?release_id=601538&group_id=119647http://www.jcoppens.com/soft/cbrpager/log.en.phphttp://www.vupen.com/english/advisories/2008/1693/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=448285https://exchange.xforce.ibmcloud.com/vulnerabilities/42741http://cvs.fedoraproject.org/viewcvs/rpms/cbrpager/devel/cbrpager-0.9.16-filen-shell-escaping.patch?rev=1.2http://secunia.com/advisories/30417http://secunia.com/advisories/30438http://secunia.com/advisories/30701http://security.gentoo.org/glsa/glsa-200806-05.xmlhttp://sourceforge.net/forum/forum.php?forum_id=827120http://sourceforge.net/project/shownotes.php?release_id=601538&group_id=119647http://www.jcoppens.com/soft/cbrpager/log.en.phphttp://www.vupen.com/english/advisories/2008/1693/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=448285https://exchange.xforce.ibmcloud.com/vulnerabilities/42741
2008-06-06
Published