| Vulnerability Name: | CVE-2000-0787 (CCN-5128) | ||||||||
| Assigned: | 2000-08-17 | ||||||||
| Published: | 2000-08-17 | ||||||||
| Updated: | 2008-09-10 | ||||||||
| Summary: | IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-00:48 xchat port inappropriately handles URLs Source: BUGTRAQ Type: Vendor Advisory 20000817 XChat URL handler vulnerabilty Source: CCN Type: BugTraq Mailing List, Thu Aug 17 2000 - 06:19:40 CDT XChat URL handler vulnerabilty Source: BUGTRAQ Type: Vendor Advisory 20000824 MDKSA-2000:039 - xchat update Source: BUGTRAQ Type: Vendor Advisory 20000825 Conectiva Linux Security Announcement - xchat Source: CCN Type: Conectiva Linux Announcement CLSA-2000:311 xchat: Commands inside URLs can be executed by xchat Source: CCN Type: BugTraq Mailing List, Fri Aug 25 2000 - 09:27:51 CDT xchat Source: MITRE Type: CNA CVE-2000-0787 Source: CCN Type: RHSA-2000:055-03 Xchat Source: CCN Type: OSVDB ID: 1524 XChat Client URL Meta Character Command Execution Source: REDHAT Type: UNKNOWN RHSA-2000:055 Source: BID Type: Vendor Advisory 1601 Source: CCN Type: BID-1601 X-Chat Command Execution Via URLs Vulnerability Source: CCN Type: X-Chat Web site Latest News Source: CCN Type: X-Chat IRC Client Index of /files/source/1.4 Source: CCN Type: MandrakeSoft Security Advisory MDKSA-2000:039 xchat Source: XF Type: UNKNOWN xchat-url-execute-commands(5128) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||