CVE-2008-3076
Netrw 125 Vim Script - Multiple Command Execution Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
7Exploited in Wild
-Decision
Descriptions
The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.
El plugin Netrw 125 en netrw.vim en Vim 7.2a.10 permite a atacantes asistidos por el usuario ejecutar comandos de su elección a través de metacaracteres de línea de comandos en utilizados para ejecutar funciones de sistema dentro de los comandos (1) mz y (2) mc, como se demostro en los casos de prueba netrw.v2 y netrw.v3. NOTA: Esta informacion existe por el arreglo incompleto de CVE-2008-2712.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-07-07 First Exploit
- 2008-07-08 CVE Reserved
- 2008-12-04 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506919 | X_refsource_confirm | |
http://marc.info/?l=bugtraq&m=121494431426308&w=2 | Mailing List | |
http://secunia.com/advisories/34418 | Third Party Advisory | |
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0324 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2008/07/08/12 | Mailing List | |
http://www.openwall.com/lists/oss-security/2008/10/20/2 | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43624 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32012 | 2008-07-07 | |
http://marc.info/?l=oss-security&m=122416184431388&w=2 | 2024-08-07 | |
http://www.openwall.com/lists/oss-security/2008/07/07/1 | 2024-08-07 | |
http://www.openwall.com/lists/oss-security/2008/07/07/4 | 2024-08-07 | |
http://www.rdancer.org/vulnerablevim-netrw.html | 2024-08-07 | |
http://www.rdancer.org/vulnerablevim-netrw.v2.html | 2024-08-07 | |
http://www.securityfocus.com/bid/30115 | 2024-08-07 |
URL | Date | SRC |
---|