ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.
References
Link | Resource |
---|---|
https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory |
https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes |
https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory |
https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes |
Configurations
History
19 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-116 |
21 Nov 2024, 07:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - Third Party Advisory | |
References | () https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - Release Notes |
05 Oct 2023, 14:14
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:cmder:cmder:*:*:*:*:*:*:*:* | |
First Time |
Cmder
Cmder cmder |
03 Oct 2023, 15:18
Type | Values Removed | Values Added |
---|---|---|
First Time |
Maximus5
Maximus5 conemu |
|
CPE | cpe:2.3:a:maximus5:conemu:*:*:*:*:*:*:*:* |
05 Apr 2023, 03:37
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - Release Notes | |
References | (MISC) https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:cmder_project:cmder:*:*:*:*:*:*:*:* cpe:2.3:a:conemu_project:conemu:*:*:*:*:*:*:*:* |
|
First Time |
Conemu Project
Cmder Project cmder Cmder Project Conemu Project conemu |
28 Mar 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-28 20:15
Updated : 2025-02-19 19:15
NVD link : CVE-2022-46387
Mitre link : CVE-2022-46387
CVE.ORG link : CVE-2022-46387
JSON object : View
Products Affected
cmder
- cmder
maximus5
- conemu
CWE