Lucene search

K
cveMitreCVE-2013-7416
HistoryDec 03, 2014 - 9:59 p.m.

CVE-2013-7416

2014-12-0321:59:00
CWE-77
mitre
web.nvd.nist.gov
22
cve
2013
7416
canto
curses
guibase.py
remote feed
arbitrary commands
shell metacharacters
url
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.005

Percentile

77.5%

canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.

Affected configurations

Nvd
Node
cantocanto_cursesRange0.9.0alpha5
OR
cantocanto_cursesMatch0.8.4
OR
cantocanto_cursesMatch0.9.0alpha2
OR
cantocanto_cursesMatch0.9.0alpha3
OR
cantocanto_cursesMatch0.9.0alpha4
VendorProductVersionCPE
cantocanto_curses*cpe:2.3:a:canto:canto_curses:*:alpha5:*:*:*:*:*:*
cantocanto_curses0.8.4cpe:2.3:a:canto:canto_curses:0.8.4:*:*:*:*:*:*:*
cantocanto_curses0.9.0cpe:2.3:a:canto:canto_curses:0.9.0:alpha2:*:*:*:*:*:*
cantocanto_curses0.9.0cpe:2.3:a:canto:canto_curses:0.9.0:alpha3:*:*:*:*:*:*
cantocanto_curses0.9.0cpe:2.3:a:canto:canto_curses:0.9.0:alpha4:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.005

Percentile

77.5%

Related for CVE-2013-7416