Baptiste Devigne (Geluchat)

2 exploits Active since Feb 2019
CVE-2019-6453 NOMISEC HIGH WORKING POC
mIRC <7.55 - Command Injection
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).
50 stars
CVSS 8.1
CVE-2019-6453 EXPLOITDB HIGH text WORKING POC
mIRC <7.55 - Command Injection
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).
CVSS 8.1