CVE-2005-1640
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.48% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- the ignition project/ignitionserver
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/15388Patch
- http://www.ignition-project.com/security/20050414-hosts-delete-owner-access-entriesExploit, Patch, Vendor Advisory
- http://secunia.com/advisories/15388Patch
- http://www.ignition-project.com/security/20050414-hosts-delete-owner-access-entriesExploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.