Lucene search

K
cveMitreCVE-2008-7070
HistoryAug 25, 2009 - 10:30 a.m.

CVE-2008-7070

2009-08-2510:30:00
CWE-94
mitre
web.nvd.nist.gov
23
cve
2008
7070
argument injection
vulnerability
kvirc 3.4.2
shiny
remote
execution
arbitrary commands
uri handler

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.041

Percentile

92.3%

Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followed by command line switches in a (1) irc:///, (2) irc6:///, (3) ircs:///, or (4) and ircs6:/// URI. NOTE: this might be due to an incomplete fix for CVE-2007-2951.

Affected configurations

Nvd
Node
kvirckvircMatch3.4.2
VendorProductVersionCPE
kvirckvirc3.4.2cpe:2.3:a:kvirc:kvirc:3.4.2:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.041

Percentile

92.3%