← All CVEs

CVE-2006-4692

medium · 5.1

Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."

5.1
CVSS
29.2%
EPSS (exploit prob.)
98th
EPSS percentile
2006-10-10
Published

AV:N/AC:H/Au:N/C:P/I:P/A:P

Weaknesses

CWE-88

Affected products

VendorProductAffected versions
microsoftwindows_server_2003all versions
microsoftwindows_server_2003all versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-4692