First published: Sat Jan 22 2005(Updated: )
Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Konversation | =0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0130 is classified as a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2005-0130, upgrade to a version of Konversation later than 0.15 that addresses the command execution issue.
CVE-2005-0130 affects users running Konversation version 0.15 due to insufficient input sanitization.
CVE-2005-0130 is a command injection vulnerability that allows remote attackers to execute arbitrary commands.
Yes, CVE-2005-0130 can be exploited in real-world scenarios where an attacker leverages unfiltered user input in IRC scripts.