CVE-2001-0150

Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:34

Type Values Removed Values Added
References () http://www.osvdb.org/7816 - Broken Link () http://www.osvdb.org/7816 - Broken Link
References () http://www.securityfocus.com/bid/2463 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/2463 - Broken Link, Third Party Advisory, VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - Patch, Vendor Advisory () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - Third Party Advisory, VDB Entry

13 Feb 2024, 17:56

Type Values Removed Values Added
References (OSVDB) http://www.osvdb.org/7816 - (OSVDB) http://www.osvdb.org/7816 - Broken Link
References (BID) http://www.securityfocus.com/bid/2463 - (BID) http://www.securityfocus.com/bid/2463 - Broken Link, Third Party Advisory, VDB Entry
References (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - Patch, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - Third Party Advisory, VDB Entry
CWE NVD-CWE-Other CWE-88

Information

Published : 2001-06-02 04:00

Updated : 2024-11-20 23:34


NVD link : CVE-2001-0150

Mitre link : CVE-2001-0150

CVE.ORG link : CVE-2001-0150


JSON object : View

Products Affected

microsoft

  • internet_explorer
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')