peter bassill · operator
$ cve CVE-2002-0652 JSON

CVE-2002-0652 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.1% (pctl 95)

Patch early

A public exploit exists.

Description

xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.15% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2002-07-03
Last modified2026-06-16

Affected (1)

VendorProduct
sgiirix

Public exploits

SourceTitleDate
exploit-dbSGI IRIX 6.x - 'rpc.xfsmd' Remote Command Execution2002-06-20

References

→ the Explorer  ·  watch your stack  ·  NVD