Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2008-5948

Disclosure Date: January 23, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.
0
Attacker Value
Unknown

CVE-2004-1052

Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.
0
Attacker Value
Unknown

CVE-2004-2612

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.
0
Attacker Value
Unknown

CVE-2004-1482

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.
0