PT-2009-2404 · Exodus · Exodus

Nine:Situations:Group

·

Published

2009-08-11

·

Updated

2018-10-11

·

CVE-2008-6935

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Exodus version 0.10
Description: The issue allows remote attackers to inject arbitrary command line arguments and overwrite arbitrary files, potentially causing a denial of service. This is achieved via encoded spaces in an im:// URI.
Recommendations: For version 0.10, consider restricting access to the im:// URI handler until a patch is available to prevent arbitrary command line argument injection and file overwrites.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6935

Affected Products

Exodus