Home / vulnerabilities quassel-commands.txt
Posted on 30 October 2008
Source : packetstormsecurity.org Link
Quassel IRC (http://quassel-irc.org/) is "a modern, cross-platform,
distributed IRC client".
A vulnerability in the CTCP handling allows an attacker to trick Quassel IRC
into sending arbitrary commands to the IRC server.
This can be used by an attacker for example to gain operator privileges on a
channel.
Details
=======
A CTCP ping where the value contains a CTCP quoted newline ('