First published: Tue Jun 24 2008(Updated: )
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | ||
Internet Explorer | ||
XChat | <=2.8.7b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2841 is considered to have a high severity due to the potential for remote command execution.
To fix CVE-2008-2841, update XChat to a version later than 2.8.7b.
Users of XChat versions 2.8.7b and earlier on Windows, particularly those using Internet Explorer, are affected by CVE-2008-2841.
CVE-2008-2841 is an argument injection vulnerability.
Yes, CVE-2008-2841 can be exploited remotely via specially crafted ircs:// URIs.