CVE-2001-0150

Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*

History

13 Feb 2024, 17:56

Type Values Removed Values Added
References () http://www.osvdb.org/7816 - () http://www.osvdb.org/7816 - Broken Link
References () http://www.securityfocus.com/bid/2463 - () http://www.securityfocus.com/bid/2463 - Broken Link, Third Party Advisory, VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/6230 - Third Party Advisory, VDB Entry
CWE NVD-CWE-Other CWE-88

23 Jul 2021, 12:18

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:ie:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*

Information

Published : 2001-06-02 04:00

Updated : 2024-02-13 17:56


NVD link : CVE-2001-0150

Mitre link : CVE-2001-0150

CVE.ORG link : CVE-2001-0150


JSON object : View

Products Affected

microsoft

  • internet_explorer
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')