CVE-2024-39844
CRITICALZNC < 1.9.1 - Remote Code Execution via modtcl KICK Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-39844. PoCs published by ph1ns.
AI-analyzed exploit summary This repository contains a functional HexChat plugin that exploits CVE-2024-39844, a remote code execution vulnerability in ZNC's modtcl module (versions < 1.9.1). The exploit leverages a command injection flaw by sending a maliciously crafted KICK command to execute arbitrary commands on the target ZNC server.
Description
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
Exploits (1)
This repository contains a functional HexChat plugin that exploits CVE-2024-39844, a remote code execution vulnerability in ZNC's modtcl module (versions < 1.9.1). The exploit leverages a command injection flaw by sending a maliciously crafted KICK command to execute arbitrary commands on the target ZNC server.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H