The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.