Unrated severityNVD Advisory· Published Dec 3, 2014· Updated May 6, 2026
CVE-2013-7416
CVE-2013-7416
Description
canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.
Affected products
5cpe:2.3:a:canto:canto_curses:*:alpha5:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:canto:canto_curses:*:alpha5:*:*:*:*:*:*range: <=0.9.0
- cpe:2.3:a:canto:canto_curses:0.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:canto:canto_curses:0.9.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:canto:canto_curses:0.9.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:canto:canto_curses:0.9.0:alpha4:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- seclists.org/oss-sec/2014/q4/826nvdExploit
- seclists.org/oss-sec/2014/q4/832nvdExploit
- github.com/themoken/canto-curses/commit/2817869f98c54975f31e2dd674c1aefa70749ccanvdExploit
- www.securityfocus.com/bid/71323nvd
- bugs.debian.org/cgi-bin/bugreport.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/98947nvd
News mentions
0No linked articles in our index yet.