Lucene search

K
cveRedhatCVE-2005-2968
HistorySep 20, 2005 - 10:03 p.m.

CVE-2005-2968

2005-09-2022:03:00
redhat
web.nvd.nist.gov
71
firefox
mozilla
command execution
vulnerability
cve-2005-2968
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.962

Percentile

99.5%

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

Affected configurations

Nvd
Node
mozillafirefoxMatch1.0.6linux
OR
mozillamozillaMatch1.7.10linux
VendorProductVersionCPE
mozillafirefox1.0.6cpe:2.3:a:mozilla:firefox:1.0.6:*:linux:*:*:*:*:*
mozillamozilla1.7.10cpe:2.3:a:mozilla:mozilla:1.7.10:*:linux:*:*:*:*:*

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.962

Percentile

99.5%