Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Brian Campbell

#20455de 53,640
12.5CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2003-1427
7.5
2003-04-26
Gkrellm · Gkrellm-Newsticker · CVE-2003-0205
Name of the Vulnerable Software and Affected Versions: gkrellm-newsticker versions before 0.3-3.1 Description: The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the `ticker title` of a URI. This can be exploited by including malicious input in the title, potentially leading to unauthorized command execution. Recommendations: For versions before 0.3-3.1, update to version 0.3-3.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of URI titles to minimize the risk of exploitation. Avoid using potentially malicious input in the `ticker title` until the issue is resolved.
PT-2003-1428
5.0
2003-04-26
Gkrellm · Gkrellm-Newsticker · CVE-2003-0206
Name of the Vulnerable Software and Affected Versions: gkrellm-newsticker versions before 0.3-3.1 Description: The issue allows remote attackers to cause a denial of service, resulting in a crash, by exploiting link or title elements that contain multiple lines. Recommendations: For versions before 0.3-3.1, update to version 0.3-3.1 or later to resolve the issue.