Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2008-5948
Disclosure Date: January 23, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.
0
Attacker Value
Unknown
CVE-2004-1052
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.
0
Attacker Value
Unknown
CVE-2004-2612
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.
0
Attacker Value
Unknown
CVE-2004-1482
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.
0