{ "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2010-2809", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "The default configuration of the binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "http://github.com/Dieterbe/uzbl/commit/9cc39cb5c9396be013b5dc2ba7e4b3eaa647e975", "refsource": "CONFIRM", "url": "http://github.com/Dieterbe/uzbl/commit/9cc39cb5c9396be013b5dc2ba7e4b3eaa647e975" }, { "name": "http://github.com/pawelz/uzbl/commit/342f292c27973c9df5f631a38bd12f14a9c5cdc2", "refsource": "CONFIRM", "url": "http://github.com/pawelz/uzbl/commit/342f292c27973c9df5f631a38bd12f14a9c5cdc2" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=621964", "refsource": "CONFIRM", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=621964" }, { "name": "[oss-security] 20100806 CVE request: uzbl before 2010.08.05: User-assisted execution of arbitrary commands caused by faulty default config", "refsource": "MLIST", "url": "http://marc.info/?l=oss-security&m=128111493509265&w=2" }, { "name": "[oss-security] 20100806 Re: CVE request: uzbl before 2010.08.05: User-assisted execution of arbitrary commands caused by faulty default config", "refsource": "MLIST", "url": "http://marc.info/?l=oss-security&m=128111994317381&w=2" }, { "name": "http://www.uzbl.org/news.php?id=29", "refsource": "CONFIRM", "url": "http://www.uzbl.org/news.php?id=29" }, { "name": "42297", "refsource": "BID", "url": "http://www.securityfocus.com/bid/42297" }, { "name": "http://www.uzbl.org/bugs/index.php?do=details&task_id=240", "refsource": "CONFIRM", "url": "http://www.uzbl.org/bugs/index.php?do=details&task_id=240" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=621965", "refsource": "CONFIRM", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=621965" }, { "name": "uzbl-atselecteduri-command-execution(61011)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61011" } ] } }