Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown
CVE-2006-6933
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Easy Chat Server 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download certain files via direct requests to files such as (1) ServerKey.pem and (2) AcceptIP.txt. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-0418
Disclosure Date: January 25, 2006 (last updated February 22, 2025)
Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.
0
Attacker Value
Unknown
CVE-2006-0223
Disclosure Date: January 16, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field.
0
Attacker Value
Unknown
CVE-2005-0919
Disclosure Date: March 29, 2005 (last updated February 22, 2025)
Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2004-2465
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown
CVE-2004-1568
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.
0
Attacker Value
Unknown
CVE-2004-2466
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.
0
Attacker Value
Unknown
CVE-2004-2467
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).
0
Attacker Value
Unknown
CVE-2004-1739
Disclosure Date: August 23, 2004 (last updated February 22, 2025)
Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.
0
Attacker Value
Unknown
CVE-2004-0678
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.
0