Back

MEDIUM

xchat: command execution when xchat is started from the browser

Published Jun 24, 2008

Description

Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of XChat as shipped with Red Hat Enterprise Linux.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 24, 2008
Updated Aug 7, 2024
Reserved Jun 24, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jun 13, 2008