bugzilla.elinks.czConfirmation
http://bugzilla.elinks.cz/show_bug.cgi?id=841 CVE-2006-5925
Links 1.00pre12 - 'smbclient' Remote Code Execution
Record summary
CVE-2006-5925 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBLinks 1.00pre12 - 'smbclient' Remote Code ExecutionExploitDB exploitby Teemu SalmelaNot analyzed1 file
ExploitDBLinks_ ELinks 'smbclient' - Remote Command ExecutionExploitDB exploitby Teemu SalmelaNot analyzed1 file
References
Showing 12 of 2920061115 Links smbclient command executionmailing list
http://marc.info/?l=full-disclosure&m=116355556512780&w=2 22905Third-party advisory
http://secunia.com/advisories/22905 22920Third-party advisory
http://secunia.com/advisories/22920 22923Third-party advisory
http://secunia.com/advisories/22923 23022Third-party advisory
http://secunia.com/advisories/23022 23132Third-party advisory
http://secunia.com/advisories/23132 23188Third-party advisory
http://secunia.com/advisories/23188 23234Third-party advisory
http://secunia.com/advisories/23234 23389Third-party advisory
http://secunia.com/advisories/23389 23467Third-party advisory
http://secunia.com/advisories/23467 24005Third-party advisory
http://secunia.com/advisories/24005