9.3
CVSSv2

CVE-2007-4396

Published: 18/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi prior to 0.8.11 allow user-assisted remote malicious users to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.

Vulnerable Product Search on Vulmon Subscribe to Product

irssi irssi

Vendor Advisories

Debian Bug report logs - #439840 CVE-2007-4398, CVE-2007-4396: Multiple CRLF injection vulnerabilities Package: irssi-scripts; Maintainer for irssi-scripts is Daniel Echeverry <epsilon@debianorg>; Source for irssi-scripts is src:irssi-scripts (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: M ...