CVE-2010-0011

The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:uzbl:uzbl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-02-25 19:30

Updated : 2024-02-28 11:41


NVD link : CVE-2010-0011

Mitre link : CVE-2010-0011

CVE.ORG link : CVE-2010-0011


JSON object : View

Products Affected

uzbl

  • uzbl
CWE
CWE-264

Permissions, Privileges, and Access Controls