FlashChat Info.PHP HTML Injection Vulnerability
BID:22411
Info
FlashChat Info.PHP HTML Injection Vulnerability
| Bugtraq ID: | 22411 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0807 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | binaryloc is credited with the discovery of this vulnerability. |
| Vulnerable: |
TUFaT FlashChat 4.7.8 TUFaT FlashChat 4.7.7 TUFaT FlashChat 4.7.6 TUFaT FlashChat 4.7.5 TUFaT FlashChat 4.7.4 TUFaT FlashChat 4.7.3 TUFaT FlashChat 4.7.2 TUFaT FlashChat 4.7.1 TUFaT FlashChat 4.7 TUFaT FlashChat 4.6.2 TUFaT FlashChat 4.6.1 TUFaT FlashChat 4.6 TUFaT FlashChat 4.5.7 |
| Not Vulnerable: | |
Discussion
FlashChat Info.PHP HTML Injection Vulnerability
FlashChat is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
FlashChat 4.7.8 and prior versions are vulnerable.
FlashChat is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
FlashChat 4.7.8 and prior versions are vulnerable.
Exploit / POC
FlashChat Info.PHP HTML Injection Vulnerability
An attacker can exploit this issue via a web client.
An attacker can exploit this issue via a web client.
Solution / Fix
FlashChat Info.PHP HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FlashChat Info.PHP HTML Injection Vulnerability
References:
References:
- FlashChat Homepage (TUFat)
- flashChat 4.7.8 Cross Site Scripting Vulnerability (binaryloc)