cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
References
Configurations
History
No history.
Information
Published : 2008-06-06 22:32
Updated : 2026-06-16 22:54
NVD link : CVE-2008-2575
Mitre link : CVE-2008-2575
CVE.ORG link : CVE-2008-2575
JSON object : View
Products Affected
fedoraproject
- fedora
jcoppens
- cbrpager
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
