Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
References
Link | Resource |
---|---|
http://www.osvdb.org/7816 | Broken Link |
http://www.securityfocus.com/bid/2463 | Broken Link Third Party Advisory VDB Entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 | Third Party Advisory VDB Entry |
http://www.osvdb.org/7816 | Broken Link |
http://www.securityfocus.com/bid/2463 | Broken Link Third Party Advisory VDB Entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 | Third Party Advisory VDB Entry |
Configurations
History
20 Nov 2024, 23:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.osvdb.org/7816 - Broken Link | |
References | () http://www.securityfocus.com/bid/2463 - Broken Link, Third Party Advisory, VDB Entry | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - Third Party Advisory, VDB Entry |
13 Feb 2024, 17:56
Type | Values Removed | Values Added |
---|---|---|
References | (OSVDB) http://www.osvdb.org/7816 - Broken Link | |
References | (BID) http://www.securityfocus.com/bid/2463 - Broken Link, Third Party Advisory, VDB Entry | |
References | (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - Patch, Vendor Advisory | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - Third Party Advisory, VDB Entry | |
CWE | CWE-88 |
Information
Published : 2001-06-02 04:00
Updated : 2024-11-20 23:34
NVD link : CVE-2001-0150
Mitre link : CVE-2001-0150
CVE.ORG link : CVE-2001-0150
JSON object : View
Products Affected
microsoft
- internet_explorer
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')