CVE-2018-1000006
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.
- Affected products
- Chromium, Github Electron, Windows 10, Windows 2008, Windows 7
- Atom Electron
- = 1.8.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 76.0% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2018-01-24
CVE-2018-1000006 at NVD
32 known exploits for CVE-2018-1000006
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2018-1000006-DEMO
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for SQL Injection in Zabbix
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for SQL Injection in Zabbix
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for SQL Injection in Zabbix
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for OS Command Injection in Atom Electron
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)
Exodus Wallet (ElectronJS Framework) Remote Code Execution
Exodus Wallet (ElectronJS Framework) - Remote Code Execution Exploit
Exodus Wallet (ElectronJS Framework) Remote Code Execution
Exodus Wallet (ElectronJS Framework) remote Code Execution
Exodus Wallet (ElectronJS Framework) - Remote Code Execution
Exploit for OS Command Injection in Atom Electron