packetstormsecurity.com
http://packetstormsecurity.com/files/136564/Hexchat-IRC-Client-2.11.0-Directory-Traversal.html CVE-2016-2087
HIGH
Hexchat IRC Client 2.11.0 - Directory Traversal
Record summary
CVE-2016-2087 has a selected CVSS score of 7.4 (high); EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHexchat IRC Client 2.11.0 - Directory TraversalExploitDB exploitby PizzaHatHackerNot analyzed1 file
References
495881vdb entry
http://www.securityfocus.com/bid/95881 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-2087 39656exploit
https://www.exploit-db.com/exploits/39656