PT-2007-5580 · Bitchx+1 · Bitchx+1
Publicado
2007-08-18
·
Atualizado
2018-10-15
·
CVE-2007-4399
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BitchX version 1.0
Description
A CRLF injection issue exists, allowing user-assisted remote attackers to execute arbitrary IRC commands. This is achieved by inserting CRLF sequences in the name of a song in an .mp3 file.
Recommendations
For version 1.0, consider disabling the xmms.bx script until a patch is available to prevent exploitation of this issue. Restrict access to .mp3 files with malicious song names to minimize the risk of arbitrary IRC command execution.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bitchx
Xmms