// For flags

CVE-2008-1965

IBM Lotus Expeditor 6.1 - URI Handler Command Execution

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.

Una vulnerabilidad de inyección de argumento en el manejador del URI CAI: en rcplauncher en IBM Lotus Expeditor Client for Desktop versiones 6.1.1 y 6.1.2, tal como es usado Lotus Symphony y posiblemente otros productos, permite a atacantes remotos ejecutar código arbitrario inyectando una opción -launcher por medio de un URI cai:, como es demostrado mediante una referencia hacia un nombre de ruta (path) compartido UNC.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-04-24 First Exploit
  • 2008-04-25 CVE Reserved
  • 2008-04-25 CVE Published
  • 2024-02-20 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Lotus Expeditor Client
Search vendor "Ibm" for product "Lotus Expeditor Client"
6.1.1
Search vendor "Ibm" for product "Lotus Expeditor Client" and version "6.1.1"
desktop
Affected
Ibm
Search vendor "Ibm"
Lotus Expeditor Client
Search vendor "Ibm" for product "Lotus Expeditor Client"
6.1.2
Search vendor "Ibm" for product "Lotus Expeditor Client" and version "6.1.2"
desktop
Affected
Ibm
Search vendor "Ibm"
Lotus Symphany
Search vendor "Ibm" for product "Lotus Symphany"
*-
Affected