CVE-2002-1393
CVE-2002-1393
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000569http://marc.info/?l=bugtraq&m=104049734911544&w=2http://marc.info/?l=bugtraq&m=104066520330397&w=2http://secunia.com/advisories/8067http://secunia.com/advisories/8103http://www.debian.org/security/2003/dsa-234http://www.debian.org/security/2003/dsa-235http://www.debian.org/security/2003/dsa-236http://www.debian.org/security/2003/dsa-237http://www.debian.org/security/2003/dsa-238http://www.debian.org/security/2003/dsa-239http://www.debian.org/security/2003/dsa-240