CVE-2005-0129
Konversation 0.15 - Remote Code Execution via Quick Buttons Channel Name Expansion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0129. PoCs published by [email protected].
AI-analyzed exploit summary The writeup describes multiple vulnerabilities in Konversation IRC client, including command injection via channel names and design flaws in QuickButtons and quick connect dialogue. These issues can lead to arbitrary command execution and denial of service.
Description
The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.
Exploits (1)
The writeup describes multiple vulnerabilities in Konversation IRC client, including command injection via channel names and design flaws in QuickButtons and quick connect dialogue. These issues can lead to arbitrary command execution and denial of service.