CVE-2008-1965
IBM Lotus Expeditor 6.1 - URI Handler Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.
Una vulnerabilidad de inyección de argumento en el manejador del URI CAI: en rcplauncher en IBM Lotus Expeditor Client for Desktop versiones 6.1.1 y 6.1.2, tal como es usado Lotus Symphony y posiblemente otros productos, permite a atacantes remotos ejecutar código arbitrario inyectando una opción -launcher por medio de un URI cai:, como es demostrado mediante una referencia hacia un nombre de ruta (path) compartido UNC.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-24 First Exploit
- 2008-04-25 CVE Reserved
- 2008-04-25 CVE Published
- 2024-02-20 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/29958 | Third Party Advisory | |
http://thomas.pollet.googlepages.com/lotusexpeditorurihandlervulnerability | X_refsource_misc | |
http://www-1.ibm.com/support/docview.wss?uid=swg21303813 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/491343/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019951 | Vdb Entry | |
http://www.securitytracker.com/id?1019952 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1394/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41990 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31706 | 2008-04-24 | |
http://archives.neohapsis.com/archives/fulldisclosure/2008-04/0640.html | 2024-08-07 | |
http://www.securityfocus.com/bid/28926 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Lotus Expeditor Client Search vendor "Ibm" for product "Lotus Expeditor Client" | 6.1.1 Search vendor "Ibm" for product "Lotus Expeditor Client" and version "6.1.1" | desktop |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Expeditor Client Search vendor "Ibm" for product "Lotus Expeditor Client" | 6.1.2 Search vendor "Ibm" for product "Lotus Expeditor Client" and version "6.1.2" | desktop |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Symphany Search vendor "Ibm" for product "Lotus Symphany" | * | - |
Affected
|