VYPR
Unrated severityNVD Advisory· Published Mar 10, 2010· Updated Apr 29, 2026

CVE-2010-0418

CVE-2010-0418

Description

The web interface in chumby one before 1.0.4 and chumby classic before 1.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a request.

Affected products

10
  • Chumby/Chumby One2 versions
    cpe:2.3:h:chumby:chumby_one:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:h:chumby:chumby_one:*:*:*:*:*:*:*:*range: <=1.0.3
    • cpe:2.3:h:chumby:chumby_one:1.0.2:*:*:*:*:*:*:*
  • cpe:2.3:h:chumby:chumby_classic:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:h:chumby:chumby_classic:*:*:*:*:*:*:*:*range: <=1.7.1
    • cpe:2.3:h:chumby:chumby_classic:0.9:*:*:*:*:*:*:*
    • cpe:2.3:h:chumby:chumby_classic:1.1:*:*:*:*:*:*:*
    • cpe:2.3:h:chumby:chumby_classic:1.2:*:*:*:*:*:*:*
    • cpe:2.3:h:chumby:chumby_classic:1.4:*:*:*:*:*:*:*
    • cpe:2.3:h:chumby:chumby_classic:1.5:*:*:*:*:*:*:*
    • cpe:2.3:h:chumby:chumby_classic:1.6:*:*:*:*:*:*:*
    • cpe:2.3:h:chumby:chumby_classic:1.7:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.