← back
CVE-2008-1965

CVE-2008-1965

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 11%
from disclosure to weapon0 days
Published on NVDApr 25
1st PoCApr 24
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.