Summary
Detail | |||
---|---|---|---|
Vendor | Quassel-Irc | First view | 2013-10-23 |
Product | Quassel Irc | Last view | 2013-12-09 |
Version | 0.7.2 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:quassel-irc:quassel_irc |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4 | 2013-12-09 | CVE-2013-6404 | Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/. |
6.8 | 2013-10-23 | CVE-2013-4422 | SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
50% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2015-05-26 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2015-376.nasl - Type: ACT_GATHER_INFO |
2015-05-18 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_49d9c28cfbad11e4b0fb00269ee29e57.nasl - Type: ACT_GATHER_INFO |
2015-05-13 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-3258.nasl - Type: ACT_GATHER_INFO |
2014-06-13 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2013-998.nasl - Type: ACT_GATHER_INFO |
2014-06-13 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2014-71.nasl - Type: ACT_GATHER_INFO |
2014-02-27 | Name: The remote Fedora host is missing a security update. File: fedora_2014-1734.nasl - Type: ACT_GATHER_INFO |
2014-02-27 | Name: The remote Fedora host is missing a security update. File: fedora_2014-1742.nasl - Type: ACT_GATHER_INFO |
2013-11-07 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_f969bad746fc11e3b6ee00269ee29e57.nasl - Type: ACT_GATHER_INFO |
2013-11-07 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-201311-03.nasl - Type: ACT_GATHER_INFO |