perlpodder before 0.5 allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast, which are executed when saving the URL to a log file. NOTE: the wget vector is already covered by CVE-2006-2548.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Perlpodder | Perlpodder | * | 0.4 (including) |
Perlpodder | Perlpodder | 0.2 (including) | 0.2 (including) |
Perlpodder | Perlpodder | 0.3 (including) | 0.3 (including) |