VDB
CVE-2006-5925
CVE-2006-5925
PUBLISHED
CVSS 7.5 HIGH
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
EPSS 33.21% · 97.0th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
33.21%
97.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| links | links | 1.00pre12 |
| elinks | elinks | 0.9.2 |
| n/a | n/a | n/a |
Timeline
- Nov 15, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 1017233 vdb
- 22920 third-party-advisory
- RHSA-2006:0742 vendor-advisory
- 22923 third-party-advisory
- GLSA-200612-16 vendor-advisory
- 22905 third-party-advisory
- 2007-0005 vendor-advisory
- 20061115 Links smbclient command execution mailing-list
- 23467 third-party-advisory
- 24005 third-party-advisory
- oval:org.mitre.oval:def:11213 vdb
- 23188 third-party-advisory
- DSA-1240 vendor-advisory
- 23234 third-party-advisory
- DSA-1228 vendor-advisory
- 1017232 vdb
- SUSE-SR:2006:027 vendor-advisory
- links-smbclient-command-execution(30299) vdb
- 24054 third-party-advisory
- 23132 third-party-advisory
…and 9 more