Record summary

CVE-2019-6453 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

Proofs of concept

3

Catalogued exploits

ExploitDBmIRC < 7.55 - 'Custom URI Protocol Handlers' Remote Command ExecutionExploitDB exploitby ProofOfCalcNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubproofofcalc/cve-2019-6453-pocRepository PoCby proofofcalcStars: 48Not analyzed3 files

4.1 MiB

GitHub

PoC details
GitHubandripwn/mIRC-CVE-2019-6453Repository PoCby andripwnStars: 1Not analyzed3 files

4.1 MiB

GitHub

PoC details

References

7