CVE Feed

    Dashboard / CVE / CVE-2008-1965

    CVE-2008-1965

    Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.

    Published:Apr 25, 2008
    Last Modified:Apr 23, 2026
    EPS:Apr 25, 2008
    EPSS Score:0.37856
    CVSS Score:9.3

    Affected Products

    Vendor
    Ibm
    Product
    Lotus Expeditor Client
    Vendor
    Ibm
    Product
    Lotus Symphany

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High