CVE-2012-2174
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.
- Affected products
- Ibm Lotus Notes
- Ibm Lotus Notes
- = 8.0, 8.0.0, 8.0.1, 8.0.2, 8.0.2.0, 8.0.2.1, 8.0.2.2, 8.0.2.3, 8.0.2.4, 8.0.2.5, 8.0.2.6, 8.5, 8.5.0.0, 8.5.0.1, 8.5.1, 8.5.1.0, 8.5.1.1, 8.5.1.2, 8.5.1.3, 8.5.1.4, 8.5.1.5, 8.5.2.0, 8.5.2.1, 8.5.2.2, 8.5.2.3, 8.5.3, 8.5.3.1
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 38.3% (98th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2012-06-20
CVE-2012-2174 at NVD
11 known exploits for CVE-2012-2174
Proof-of-concept code and exploit modules indexed by Sploitus
IBM Lotus Notes Client URL Handler Command Injection Vulnerability
IBM Lotus Notes Client URL Handler - Command Injection (Metasploit)
IBM Lotus Notes Client URL Handler Command Injection
IBM Lotus Notes Client URL Handler Command Injection
IBM Lotus Notes URL Handler Command Execution
IBM Lotus Notes URL Handler Command Execution
IBM Lotus Notes URL Handler Command Execution
IBM Lotus Notes URL Handler Command Execution
IBM Lotus Notes 8.x "notes" URI处理器漏洞
DSquare Exploit Pack: D2SEC_NOTESURL
IBM Lotus Notes Client URL Handler Command Injection