CVE-2008-2841

Microsoft Internet Explorer < 2.8.7b - Code Injection

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2841. PoCs published by securfrog.

AI-analyzed exploit summary This exploit leverages a URI handler vulnerability in Xchat <= 2.8.7b on Windows by injecting a command via a malformed IRCS:// URI. The PoC uses a quote character to break out of the URL parameter and append a --command argument to execute arbitrary commands (e.g., launching calc.exe).

Description

Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.

Exploits (1)

exploitdb WORKING POC VERIFIED
by securfrog · htmlremotewindows
https://www.exploit-db.com/exploits/5795

This exploit leverages a URI handler vulnerability in Xchat <= 2.8.7b on Windows by injecting a command via a malformed IRCS:// URI. The PoC uses a quote character to break out of the URL parameter and append a --command argument to execute arbitrary commands (e.g., launching calc.exe).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Xchat <= 2.8.7b
No auth needed
Prerequisites: Victim must be using Windows with Xchat installed · Victim must be connected to an IRC server · Victim must be using Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29696
Various Sources x_refsource_confirm
http://forum.xchat.org/viewtopic.php?t=4218
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43065
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5795
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30695

Scores

EPSS 0.1538
EPSS Percentile 96.4%

Details

CWE
CWE-94
Status published
Products (2)
microsoft/internet_explorer
xchat/xchat < 2.8.7b
Published Jun 24, 2008
Tracked Since Feb 18, 2026