CVE-2002-0652 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 9.1% (pctl 95)
Patch early
A public exploit exists.
Description
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 9.15% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-07-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sgi | irix |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SGI IRIX 6.x - 'rpc.xfsmd' Remote Command Execution | 2002-06-20 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20020605-01-I
- ftp://patches.sgi.com/support/free/security/advisories/20020606-01-I
- http://marc.info/?l=bugtraq&m=102459162909825&w=2
- ftp://patches.sgi.com/support/free/security/advisories/20020605-01-I
- ftp://patches.sgi.com/support/free/security/advisories/20020606-01-I
- http://marc.info/?l=bugtraq&m=102459162909825&w=2
→ the Explorer · watch your stack · NVD