CVE-2006-4692
Microsoft Windows XP <SP2 - Command Injection
Title source: llmDescription
Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
References (12)
Scores
EPSS
0.6664
EPSS Percentile
98.5%
Classification
CWE
CWE-88
Status
draft
Affected Products (4)
microsoft/windows_server_2003
microsoft/windows_server_2003
microsoft/windows_xp
microsoft/windows_xp
Timeline
Published
Oct 10, 2006
Tracked Since
Feb 18, 2026