20000817 XChat URL handler vulnerabiltymailing list
http://archives.neohapsis.com/archives/bugtraq/2000-08/0215.html CVE-2000-0787
X-Chat 1.2/1.3/1.4/1.5 - Command Execution via URLs
Record summary
CVE-2000-0787 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBX-Chat 1.2/1.3/1.4/1.5 - Command Execution via URLsExploitDB exploitby zenith parsecNot analyzed1 file
References
620000824 MDKSA-2000:039 - xchat updatemailing list
http://archives.neohapsis.com/archives/bugtraq/2000-08/0301.html 20000825 Conectiva Linux Security Announcement - xchatmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-08/0305.html RHSA-2000:055Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-055.html 1601vdb entry
http://www.securityfocus.com/bid/1601 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0787