← Vulnerability feed

Vulnerability record · CVE-2006-5925 · published 15 November 2006

CVE-2006-5925: Elinks vulnerability

EElinks · Elinks

Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.

7.5 CVSS 2.0 High EPSS 8.3% · top 5.3%
7.5CVSS 2.0 base score
8.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
56References
16 Jun 2026Last modified by NVD

Description

Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugzilla.elinks.cz/show_bug.cgi?id=841
http://marc.info/?l=full-disclosure&m=116355556512780&w=2
http://secunia.com/advisories/22905 Vendor Advisory
http://secunia.com/advisories/22920 Vendor Advisory
http://secunia.com/advisories/22923 Vendor Advisory
http://secunia.com/advisories/23022 Vendor Advisory
http://secunia.com/advisories/23132 Vendor Advisory
http://secunia.com/advisories/23188 Vendor Advisory
http://secunia.com/advisories/23234 Vendor Advisory
http://secunia.com/advisories/23389 Vendor Advisory
http://secunia.com/advisories/23467 Vendor Advisory
http://secunia.com/advisories/24005 Vendor Advisory
http://secunia.com/advisories/24054 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200612-16.xml
http://securitytracker.com/id?1017232
http://securitytracker.com/id?1017233
http://www.debian.org/security/2006/dsa-1228
http://www.debian.org/security/2006/dsa-1240
http://www.gentoo.org/security/en/glsa/glsa-200701-27.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:216
http://www.novell.com/linux/security/advisories/2006_27_sr.html
http://www.redhat.com/support/errata/RHSA-2006-0742.html
http://www.securityfocus.com/archive/1/451870/100/200/threaded
http://www.securityfocus.com/bid/21082
http://www.trustix.org/errata/2007/0005
https://exchange.xforce.ibmcloud.com/vulnerabilities/30299
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11213
https://www.debian.org/security/2006/dsa-1226
http://bugzilla.elinks.cz/show_bug.cgi?id=841
http://marc.info/?l=full-disclosure&m=116355556512780&w=2
http://secunia.com/advisories/22905 Vendor Advisory
http://secunia.com/advisories/22920 Vendor Advisory
http://secunia.com/advisories/22923 Vendor Advisory
http://secunia.com/advisories/23022 Vendor Advisory
http://secunia.com/advisories/23132 Vendor Advisory
http://secunia.com/advisories/23188 Vendor Advisory
http://secunia.com/advisories/23234 Vendor Advisory
http://secunia.com/advisories/23389 Vendor Advisory
http://secunia.com/advisories/23467 Vendor Advisory
http://secunia.com/advisories/24005 Vendor Advisory

Track CVE-2006-5925 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-5925), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.