Argument Injection Vulnerability in IBM Lotus Expeditor Client for Desktop
CVE-2008-1965
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 25 April 2008
What is CVE-2008-1965?
An argument injection flaw exists in the cai: URI handler within the rcplauncher of IBM Lotus Expeditor Client for Desktop. This vulnerability allows remote attackers to execute arbitrary code through specially crafted cai: URI requests that inject malicious -launcher options, potentially leading to significant security risks. The affected versions are 6.1.1 and 6.1.2, commonly utilized in Lotus Symphony and possibly other IBM products.