Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin...
Vulnerability Description
Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4401
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/25281
- http://securityreason.com/securityalert/3036
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065227.html
- http://www.securityfocus.com/archive/1/476283/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35985
- http://wouter.coekaerts.be/site/security/nowplaying
- http://secunia.com/advisories/26491
More from mirc
View All →Affected Vendor
mirc
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.