{
    "id": "CVE-2002-0652",
    "published": "2002-07-03 04:00:00",
    "last_modified": "2026-06-16 21:57:52",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().",
    "epss_score": "0.09148",
    "epss_percentile": "0.95183",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-03 18:17:03",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "sgi",
            "product": "irix"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "21571",
            "title": "SGI IRIX 6.x - 'rpc.xfsmd' Remote Command Execution",
            "date": "2002-06-20",
            "url": "https://www.exploit-db.com/exploits/21571"
        }
    ],
    "refs_list": [
        "ftp://patches.sgi.com/support/free/security/advisories/20020605-01-I",
        "ftp://patches.sgi.com/support/free/security/advisories/20020606-01-I",
        "http://marc.info/?l=bugtraq&m=102459162909825&w=2",
        "ftp://patches.sgi.com/support/free/security/advisories/20020605-01-I",
        "ftp://patches.sgi.com/support/free/security/advisories/20020606-01-I",
        "http://marc.info/?l=bugtraq&m=102459162909825&w=2"
    ]
}