PT-2009-3370 · Znc · Znc
Florian Weimer
·
Published
2009-03-03
·
Updated
2009-06-09
·
CVE-2009-0759
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZNC versions prior to 0.066
Description
The issue allows remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors. This is due to multiple CRLF injection vulnerabilities in the webadmin component of ZNC.
Recommendations
For versions prior to 0.066, update to version 0.066 or later to resolve the issue.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Znc