7.5

CVE-2004-0411

The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
KdeKonqueror Version <= 3.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.49% 0.901
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

http://marc.info/?l=bugtraq&m=108481412427344&w=2
Third Party Advisory
Mailing List
http://www.securityfocus.com/advisories/6717
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/advisories/6743
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/363225
Third Party Advisory
Vendor Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/10358
Third Party Advisory
Broken Link
VDB Entry