I found an argument injection vulnerability
related to the handling of the BROWSER
environment variable
in sensible-browser
.
This lead me (and others) to a a few other argument and shell command injection
vulnerabilities in BROWSER
processing and browser invocation in general.
↧
Argument and shell command injections in browser invocation
↧