7.5
CVSSv2

CVE-2000-0787

Published: 20/10/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

IRC Xchat client versions 1.4.2 and previous versions allows remote malicious users to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.

Vulnerable Product Search on Vulmon Subscribe to Product

xchat xchat 1.3.13

xchat xchat 1.4

xchat xchat 1.2.1

xchat xchat 1.3.10

xchat xchat 1.3.11

xchat xchat 1.3.12

xchat xchat 1.4.2

xchat xchat 1.5.6

xchat xchat 1.5.xdev

xchat xchat 1.3.9

xchat xchat 1.4.1

Exploits

source: wwwsecurityfocuscom/bid/1601/info A vulnerability exists in versions 142 and earlier of the X-Chat IRC client By supplying commands enclosed in backticks (``) in URL's sent to X-Chat, it is possible to execute arbitrary commands should the X-Chat user decide to view the link by clicking on it This is due to the manner in which ...