CVE-2017-9557
Summary
| CVE | CVE-2017-9557 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-12 15:29:00 UTC |
| Updated | 2021-03-26 17:56:00 UTC |
| Description | register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Echatserver | Easy Chat Server | All | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.0 | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.1 | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.2 | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.5 | All | All | All |
| Application | Efs Software | Easy Chat Server | 3.0 | All | All | All |
| Application | Efs Software | Easy Chat Server | 3.1 | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.0 | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.1 | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.2 | All | All | All |
| Application | Efs Software | Easy Chat Server | 2.5 | All | All | All |
| Application | Efs Software | Easy Chat Server | 3.0 | All | All | All |
| Application | Efs Software | Easy Chat Server | 3.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EFS Easy Chat Server 3.1 - Password Disclosure | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.