peter bassill · operator
$ cve CVE-2003-1308 JSON

CVE-2003-1308 EXPLOIT

4.6
MEDIUM · CVSS 2.0 · EPSS 1.3% (pctl 70)

Patch early

A public exploit exists.

Description

CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.

Scoring

CVSS4.6 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS1.34% — more likely to be exploited than 70% of all CVEs
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
fvwmfvwm

Public exploits

SourceTitleDate
exploit-dbFVWM 2.4/2.5 - fvwm-menu-Directory Command Execution2003-12-05

References

→ the Explorer  ·  watch your stack  ·  NVD