Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4225-968q-h9xp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.

EPSS

Процентиль: 82%
0.01713
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 15 лет назад

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.

EPSS

Процентиль: 82%
0.01713
Низкий

Дефекты

CWE-20