kicq IRC客户端漏洞

kicq IRC客户端漏洞

漏洞ID 1106217 漏洞类型 未知
发布时间 2001-02-14 更新时间 2005-07-26
图片[1]-kicq IRC客户端漏洞-安全小百科CVE编号 CVE-2001-0274
图片[2]-kicq IRC客户端漏洞-安全小百科CNNVD-ID CNNVD-200105-002
漏洞平台 Unix CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/20660
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200105-002
|漏洞详情
kicqIRC客户端1.0.0版本以及可能之后的版本存在漏洞。远程攻击者可以借助URL中的shell元字符执行任意命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/2443/info

KICQ is an ICQ-compatible interactive messaging client for Unix. Versions of KICQ are vulnerable to remote execution of arbitrary commands embedded in URLs.

A maliciously-composed URL containing shell metacharacters and shell commands can be sent in an instant message by an attacker.

When the KICQ user clicks this link, the hostile code contained in the URL will execute with the privilege level of the user running KICQ. 

* Attacker composes malicious URL, ie:

http://www.attack.com/index.html'&xterm&'truehttp://www.attack.com </external/http://www.attack.com/index.html'&xterm&'truehttp://www.attack.com>..............................................................

('.' characters = spaces)

* To the target user, the above URL appears to be:

"http://www.attack.com/" </external/http://www.attack.com/>

* When the target user opens the URL, the shell commands contained within it (ie 'xterm') will be executed, potentially without warning to the user.
|参考资料

来源:BUGTRAQ
名称:20010303Re:Securityholeinkicq
链接:http://archives.neohapsis.com/archives/bugtraq/2001-02/0536.html
来源:BUGTRAQ
名称:20010214Securityholeinkicq
链接:http://archives.neohapsis.com/archives/bugtraq/2001-02/0276.html
来源:XF
名称:kicq-execute-commands(6112)
链接:http://xforce.iss.net/xforce/xfdb/6112

相关推荐: Gallery Remote Global Variable Injection Vulnerability

Gallery Remote Global Variable Injection Vulnerability 漏洞ID 1098989 漏洞类型 Input Validation Error 发布时间 2004-01-26 更新时间 2004-01-26 CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享