Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via "--" style options in the q_Host parameter.
Threat-Mapped Scoring
Score: 3.0
Priority: P2 - Serious (High)
S1 – Steal Customer Account Information
EPSS
Score: 0.01295 Percentile:
0.78811
CVSS Scoring
CVSS v2 Score: 6.4
Severity:
Mapped CWE(s)
CWE-88
: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
All CAPEC(s)
CAPEC-137: Parameter Injection
CAPEC-174: Flash Parameter Injection
CAPEC-41: Using Meta-characters in E-mail Headers to Inject Malicious Payloads