CVE-2005-0130
Summary
| CVE | CVE-2005-0130 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-04-14 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Berlios | Konversation | 0.15 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - Konversation Shell Command Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.kde.org/info/security/advisory-20050121-1.txt | af854a3a-2127-422b-91ae-364da2661108 | www.kde.org | |
| SecurityTracker.com Archives - KDE Konversation Bugs May Allow a Remote User to Cause Command Execution on a Target User's System | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Gentoo Linux Documentation -- Konversation: Various vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Konversation IRC Client Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [Full-Disclosure] Multiple vulnerabilities in Konversation | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| Secunia - Advisories - Gentoo update for konversation | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 'Multiple vulnerabilities in Konversation' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.