CVE-2010-2809 describes a command injection vulnerability in Uzbl versions prior to 2010.08.05. The flaw arises from the default configuration of the <Button2> binding, which improperly handles the @SELECTED_URI feature, allowing user-assisted remote attackers to execute arbitrary commands through specially crafted HTML links. This vulnerability has a CVSS score of 6.8, indicating a medium severity with network access, medium attack complexity, and potential for partial confidentiality, integrity, and availability impacts. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, an exploit demonstrating command injection via mouse button bindings is publicly available on ExploitDB. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2010.04.03CPE matchmatch criteria | cpe:2.3:a:uzbl:uzbl:*:*:*:*:*:*:*:* | ||
2009.12.22CPE matchmatch criteria | cpe:2.3:a:uzbl:uzbl:2009.12.22:*:*:*:*:*:*:* | ||
2010.01.04CPE matchmatch criteria | cpe:2.3:a:uzbl:uzbl:2010.01.04:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.