X-Chat Command Execution Via URLs...

- AV AC AU C I A
发布: 2000-08-17
修订: 2025-04-13

A vulnerability exists in versions 1.4.2 and earlier of the X-Chat IRC client. By supplying commands enclosed in backticks (``) in URL's sent to X-Chat, it is possible to execute arbitrary commands should the X-Chat user decide to view the link by clicking on it. This is due to the manner in which X-Chat launches pages for viewing. X-Chat launches Netscape without checking for shell metacharacters in the supplied URL. This allows for an attacker to exploit shell expansion capabilities to execute commands as the user running Netscape.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息