CVE-2006-5925 details a remote code execution vulnerability in Links web browser 1.00pre12 and Elinks 0.9.2, specifically when the smbclient utility is installed. Attackers can exploit this by injecting shell metacharacters into smb:// URIs, typically through PUT and GET statements. This vulnerability has a high CVSS score of 7.5, indicating it is remotely exploitable with low attack complexity and no authentication required, leading to arbitrary code execution. Although not listed on CISA's Known Exploited Vulnerabilities catalog, public exploit code is available on ExploitDB, and the CVE is on a "Hot List," suggesting ongoing relevance or tracking within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.2CPE matchmatch criteria | cpe:2.3:a:elinks:elinks:0.9.2:*:*:*:*:*:*:* | ||
1.00pre12CPE matchmatch criteria | cpe:2.3:a:links:links:1.00pre12:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.