{"api_version":"1","generated_at":"2026-07-23T05:02:51+00:00","cve":"CVE-2005-0130","urls":{"html":"https://cve.report/CVE-2005-0130","api":"https://cve.report/api/cve/CVE-2005-0130.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0130","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0130"},"summary":{"title":"CVE-2005-0130","description":"Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-04-14 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/13919","name":"http://secunia.com/advisories/13919","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Konversation Shell Command Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kde.org/info/security/advisory-20050121-1.txt","name":"http://www.kde.org/info/security/advisory-20050121-1.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1012972","name":"http://securitytracker.com/id?1012972","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - KDE Konversation Bugs May Allow a Remote User to Cause Command Execution on a Target User's System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Konversation: Various vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12312","name":"http://www.securityfocus.com/bid/12312","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Konversation IRC Client Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19008","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19008","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] Multiple vulnerabilities in Konversation","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/13989","name":"http://secunia.com/advisories/13989","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Gentoo update for konversation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=110626383310742&w=2","name":"http://marc.info/?l=bugtraq&m=110626383310742&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Multiple vulnerabilities in Konversation' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0130","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0130","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"130","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"berlios","cpe5":"konversation","cpe6":"0.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:05:24.998Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"13919","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/13919"},{"name":"20050119 Multiple vulnerabilities in Konversation","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kde.org/info/security/advisory-20050121-1.txt"},{"name":"12312","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12312"},{"name":"13989","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/13989"},{"name":"konversation-perlscript-execute-code(19008)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19008"},{"name":"GLSA-200501-34","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml"},{"name":"20050119 Multiple vulnerabilities in Konversation","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110626383310742&w=2"},{"name":"1012972","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1012972"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-01-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-11T16:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"13919","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/13919"},{"name":"20050119 Multiple vulnerabilities in Konversation","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kde.org/info/security/advisory-20050121-1.txt"},{"name":"12312","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12312"},{"name":"13989","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/13989"},{"name":"konversation-perlscript-execute-code(19008)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19008"},{"name":"GLSA-200501-34","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml"},{"name":"20050119 Multiple vulnerabilities in Konversation","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110626383310742&w=2"},{"name":"1012972","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1012972"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0130","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"13919","refsource":"SECUNIA","url":"http://secunia.com/advisories/13919"},{"name":"20050119 Multiple vulnerabilities in Konversation","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html"},{"name":"http://www.kde.org/info/security/advisory-20050121-1.txt","refsource":"CONFIRM","url":"http://www.kde.org/info/security/advisory-20050121-1.txt"},{"name":"12312","refsource":"BID","url":"http://www.securityfocus.com/bid/12312"},{"name":"13989","refsource":"SECUNIA","url":"http://secunia.com/advisories/13989"},{"name":"konversation-perlscript-execute-code(19008)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19008"},{"name":"GLSA-200501-34","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml"},{"name":"20050119 Multiple vulnerabilities in Konversation","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110626383310742&w=2"},{"name":"1012972","refsource":"SECTRACK","url":"http://securitytracker.com/id?1012972"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0130","datePublished":"2005-01-22T05:00:00.000Z","dateReserved":"2005-01-20T00:00:00.000Z","dateUpdated":"2024-08-07T21:05:24.998Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-04-14 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:berlios:konversation:0.15:*:*:*:*:*:*:*","matchCriteriaId":"A46AE693-7BBD-431A-BC50-B524B057F218"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"130","Ordinal":"1","Title":"CVE-2005-0130","CVE":"CVE-2005-0130","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"130","Ordinal":"1","NoteData":"Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.","Type":"Description","Title":"CVE-2005-0130"},{"CveYear":"2005","CveId":"130","Ordinal":"2","NoteData":"2005-01-22","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"130","Ordinal":"3","NoteData":"2017-07-11","Type":"Other","Title":"Modified"}]}}}