4.6
CVSSv2

CVE-2003-1308

Published: 31/12/2003 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x prior to 2.5.10 and 2.4.x prior to 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.

Vulnerable Product Search on Vulmon Subscribe to Product

fvwm fvwm

Exploits

source: wwwsecurityfocuscom/bid/9161/info It has been reported that FVWM may be prone to a command execution vulnerability that may allow an attacker to execute malicious commands on a vulnerable system It has been reported that the fvwm-menu-directory component does not properly sanitize user input and allows a user with write permissio ...