Arbitrary Command Execution via Smileys in Gaim

Arbitrary Command Execution via Smileys in Gaim

CVE-2004-0784 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.

Learn more about our Web Application Penetration Testing UK.