PT-2024-10546 · Mikexstudios · Xcomic

Kevin

·

Published

2024-10-17

·

Updated

2024-11-14

·

CVE-2005-10003

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions mikexstudios Xcomic versions up to 0.8.2
Description A critical vulnerability has been found in mikexstudios Xcomic, affecting an unknown part of the software. The manipulation of the cmd argument leads to os command injection, allowing for remote attacks. The complexity of an attack is rather high, and the exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Recommendations For versions up to 0.8.2, upgrade to version 0.8.3 to address this issue. As a temporary workaround, consider restricting the use of the cmd argument to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2005-10003

Affected Products

Xcomic