cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
References
Configurations
History
No history.
Information
Published : 2008-06-06 22:32
Updated : 2025-04-09 00:30
NVD link : CVE-2008-2575
Mitre link : CVE-2008-2575
CVE.ORG link : CVE-2008-2575
JSON object : View
Products Affected
jcoppens
- cbrpager
fedoraproject
- fedora
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')