netrik: insufficient escaping
| Package(s): | netrik | CVE #(s): | CVE-2006-6678 | ||||
| Created: | January 22, 2007 | Updated: | January 24, 2007 | ||||
| Description: | It has been discovered that netrik, a text mode WWW browser with vi like keybindings, doesn't properly sanitize temporary filenames when editing textareas which could allow attackers to execute arbitrary commands via shell metacharacters. | ||||||
| Alerts: |
| ||||||
