CVE-2011-0912

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a –launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.

Date published : 2011-02-08

http://www-01.ibm.com/support/docview.wss?uid=swg21461514

http://zerodayinitiative.com/advisories/ZDI-11-051/