CVE-2004-1165
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
- Affected products
- Konqueror, Red Hat, Kdebase, Kdebase-Devel
- Kde Kdelibs
- = 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.2, 3.2.1, 3.2.2
- Kde Konqueror
- = 3.3.1
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 4.4% (91th percentile)
- NVD status
- Modified
- Published
- 2004-12-10
CVE-2004-1165 at NVD
1 known exploit for CVE-2004-1165
Proof-of-concept code and exploit modules indexed by Sploitus