### [CVE-2008-5749](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5749) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description ** DISPUTED ** Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission." ### POC #### Reference - http://securityreason.com/securityalert/4821 - https://www.exploit-db.com/exploits/7566 #### Github No PoCs found on GitHub currently.