Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95vj-g5cr-7j53

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).

mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).

EPSS

Процентиль: 99%
0.84944
Высокий

8.1 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).

EPSS

Процентиль: 99%
0.84944
Высокий

8.1 High

CVSS3

Дефекты

CWE-88