Salut a tous,
KVIRC est compris dans la mdk6.1, c'est un client irc graphique tres bien
etc etc..mais qui comprend un bug de s�curit�, :

KVIrc local file request vulnerability
Oct, 09 1999 - 23:20
contributed by: cube
KVIrc (http://www.kvirc.org/) is free IRC client for UNIX / X-Windows. This
IRC client in version 0.9.0 is vulnerable to an attack that enables remote
users to request for download local files located on the system of an KVIrc
user. That's done by posting something like following command at the
channel where KVIrc user is offering files:
!userx ../../../../../../../etc/passwd
where 'userx' is that KVIrc user. Latest KVIrc version 1.0.0 and CVS
versions are not vulnerable.



Pass� donc a la verson 1.0 dispo sur le site de KVIRC pou rplus de
s�curit�..



tchesmeli serge.

Répondre à