---
cve: "CVE-2010-2809"
severity: "LOW"
cvss: 3.1
epss: "7.4%"
vendor: "n/a"
kev: false
exploited: false
published: "2010-08-19 22:00:02"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T21:21:42+02:00"
---

# CVE-2010-2809

> 3.1 LOW · 🧪 PoC

## Beschreibung

The default configuration of the  binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.

## Exploit-Evidenz

- [EDB-34426 — uzbl 'uzbl-core' - '@SELECTED_URI' Mouse Button Bindings Command Injection](https://www.exploit-db.com/exploits/34426) ✅

## Referenzen

- <http://github.com/Dieterbe/uzbl/commit/9cc39cb5c9396be013b5dc2ba7e4b3eaa647e975>
- <http://github.com/pawelz/uzbl/commit/342f292c27973c9df5f631a38bd12f14a9c5cdc2>
- <https://bugzilla.redhat.com/show_bug.cgi?id=621964>
- <http://marc.info/?l=oss-security&m=128111493509265&w=2>
- <http://marc.info/?l=oss-security&m=128111994317381&w=2>
- <http://www.uzbl.org/news.php?id=29>
- <http://www.securityfocus.com/bid/42297>
- <http://www.uzbl.org/bugs/index.php?do=details&task_id=240>
- <https://bugzilla.redhat.com/show_bug.cgi?id=621965>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/61011>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2010-2809) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
