{"id":"CVE-2012-2085","details":"The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribute.","modified":"2026-04-10T03:42:17.260757Z","published":"2012-08-28T17:55:04Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/48708"},{"type":"ADVISORY","url":"http://secunia.com/advisories/48794"},{"type":"ADVISORY","url":"http://security.gentoo.org/glsa/glsa-201208-04.xml"},{"type":"EVIDENCE","url":"https://trac.gajim.org/changeset/bc296e96ac10"},{"type":"FIX","url":"https://trac.gajim.org/changeset/bc296e96ac10"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/08/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/08/2"},{"type":"WEB","url":"http://www.securityfocus.com/bid/52943"},{"type":"WEB","url":"https://trac.gajim.org/ticket/7031"}],"schema_version":"1.7.5"}