Vulnerabilities > CVE-2004-2553 - Unspecified vulnerability in the Ignition Project Ignitionserver 0.1.2/0.1.2R1/0.1.2R2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN the-ignition-project
nessus
Summary
The Ignition Project ignitionServer 0.1.2 through 0.1.2-R2 allows remote authenticated users with local IRC operator privileges to obtain global IRC operator privileges by using the unofficial umode command with the +ORD argument.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Misc. |
NASL id | IRCD_IGNITION_IRCOP_VULN.NASL |
description | The remote host is running a version of the IgnitionServer IRC service which might be vulnerable to a flaw that lets a remote attacker gain elevated privileges on the system. A local IRC operator can supply an unofficial command to the server to obtain elevated privileges and become a global IRC operator. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14388 |
published | 2004-08-27 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14388 |
title | ignitionServer umode Command Global Operator Privilege Escalation |
References
- http://cvs.sourceforge.net/viewcvs.py/ignition/ignitionserver/docs/security/20040302-operator-privilege-escalation.txt?view=markup
- http://cvs.sourceforge.net/viewcvs.py/ignition/ignitionserver/docs/security/20040302-operator-privilege-escalation.txt?view=markup
- http://secunia.com/advisories/11017
- http://secunia.com/advisories/11017
- http://securitytracker.com/id?1009301
- http://securitytracker.com/id?1009301
- http://sourceforge.net/tracker/index.php?func=detail&aid=891555&group_id=96071&atid=613526
- http://sourceforge.net/tracker/index.php?func=detail&aid=891555&group_id=96071&atid=613526
- http://www.osvdb.org/4121
- http://www.osvdb.org/4121
- http://www.securityfocus.com/bid/9783
- http://www.securityfocus.com/bid/9783
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15363
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15363