CVE-2013-7416

canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canto:canto_curses:*:alpha5:*:*:*:*:*:*
cpe:2.3:a:canto:canto_curses:0.8.4:*:*:*:*:*:*:*
cpe:2.3:a:canto:canto_curses:0.9.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:canto:canto_curses:0.9.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:canto:canto_curses:0.9.0:alpha4:*:*:*:*:*:*

History

No history.

Information

Published : 2014-12-03 21:59

Updated : 2023-12-10 11:31


NVD link : CVE-2013-7416

Mitre link : CVE-2013-7416

CVE.ORG link : CVE-2013-7416


JSON object : View

Products Affected

canto

  • canto_curses
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')