cbcvebase.
CVE-2008-6235
published 2009-02-21

CVE-2008-6235: The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the…

PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.99%
85.8th percentile
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianvim< vim 2:7.2.148-1 (bookworm)vim 2:7.2.148-1 (bookworm)
vimvim
vimvim
vimvim>= 0 < 2:7.2.148-12:7.2.148-1
vimvim>= 0 < 2:7.2.148-12:7.2.148-1
vimvim>= 0 < 2:7.2.148-12:7.2.148-1
vimvim>= 0 < 2:7.2.148-12:7.2.148-1

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.