CVE-2008-1965
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 11%
from disclosure to weapon0 days
Published on NVDApr 25
1st PoCApr 24
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/31706⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/fulldisclosure/2008-04/0640.htmlhttp://secunia.com/advisories/29958https://exchange.xforce.ibmcloud.com/vulnerabilities/41990http://thomas.pollet.googlepages.com/lotusexpeditorurihandlervulnerabilityhttp://www-1.ibm.com/support/docview.wss?uid=swg21303813http://www.securityfocus.com/archive/1/491343/100/0/threadedhttp://www.securityfocus.com/bid/28926http://www.securitytracker.com/id?1019951http://www.securitytracker.com/id?1019952http://www.vupen.com/english/advisories/2008/1394/references