|
|
Log in / Subscribe / Register

netrik: insufficient escaping

Package(s):netrik CVE #(s):CVE-2006-6678
Created:January 22, 2007 Updated:January 24, 2007
Description: It has been discovered that netrik, a text mode WWW browser with vi like keybindings, doesn't properly sanitize temporary filenames when editing textareas which could allow attackers to execute arbitrary commands via shell metacharacters.
Alerts:
Debian DSA-1251-1 netrik 2007-01-21

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds