{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2008-1368", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an authenticated FTP connection established earlier in the same browser session, as demonstrated using a DELE command, a variant or possibly a regression of CVE-2004-1166. NOTE: a trailing \"//\" can force Internet Explorer to try to reuse an existing authenticated connection." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "20080313 Rapid7 Advisory R7-0032: Microsoft Internet Explorer FTP Command Injection Vulnerability", "refsource" : "BUGTRAQ", "url" : "http://www.securityfocus.com/archive/1/489500/100/0/threaded" }, { "name" : "http://www.rapid7.com/advisories/R7-0032.jsp", "refsource" : "MISC", "url" : "http://www.rapid7.com/advisories/R7-0032.jsp" }, { "name" : "28208", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/28208" }, { "name" : "ADV-2008-0870", "refsource" : "VUPEN", "url" : "http://www.vupen.com/english/advisories/2008/0870" }, { "name" : "29346", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/29346" }, { "name" : "3750", "refsource" : "SREASON", "url" : "http://securityreason.com/securityalert/3750" } ] } }