CVE-2007-4396

Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:irssi:irssi:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:35

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065227.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065227.html -
References () http://osvdb.org/39568 - () http://osvdb.org/39568 -
References () http://secunia.com/advisories/26483 - () http://secunia.com/advisories/26483 -
References () http://securityreason.com/securityalert/3036 - () http://securityreason.com/securityalert/3036 -
References () http://wouter.coekaerts.be/site/security/nowplaying - () http://wouter.coekaerts.be/site/security/nowplaying -
References () http://www.securityfocus.com/archive/1/476283/100/0/threaded - () http://www.securityfocus.com/archive/1/476283/100/0/threaded -
References () http://www.securityfocus.com/bid/25281 - () http://www.securityfocus.com/bid/25281 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/35985 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/35985 -

Information

Published : 2007-08-18 21:17

Updated : 2024-11-21 00:35


NVD link : CVE-2007-4396

Mitre link : CVE-2007-4396

CVE.ORG link : CVE-2007-4396


JSON object : View

Products Affected

irssi

  • irssi