EFS Software Easy Chat Server 'registresult.htm' Authentication Bypass Vulnerability
BID:33967
Info
EFS Software Easy Chat Server 'registresult.htm' Authentication Bypass Vulnerability
| Bugtraq ID: | 33967 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2009 12:00AM |
| Updated: | Mar 04 2009 02:16PM |
| Credit: | Mountassif Moad |
| Vulnerable: |
EFS Software Easy Chat Server 2.2 |
| Not Vulnerable: | |
Discussion
EFS Software Easy Chat Server 'registresult.htm' Authentication Bypass Vulnerability
EFS Software Easy Chat Server is prone to an authentication-bypass vulnerability because it fails to perform adequate authentication checks.
Attackers can exploit this vulnerability to gain unauthorized access to the affected application, which may aid in further attacks.
Easy Chat Server 2.2 is vulnerable; other versions may also be affected.
EFS Software Easy Chat Server is prone to an authentication-bypass vulnerability because it fails to perform adequate authentication checks.
Attackers can exploit this vulnerability to gain unauthorized access to the affected application, which may aid in further attacks.
Easy Chat Server 2.2 is vulnerable; other versions may also be affected.
Exploit / POC
EFS Software Easy Chat Server 'registresult.htm' Authentication Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following exploit is available:
Attackers can exploit this issue via a browser.
The following exploit is available:
Solution / Fix
EFS Software Easy Chat Server 'registresult.htm' Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
EFS Software Easy Chat Server 'registresult.htm' Authentication Bypass Vulnerability
References:
References:
- Easy Chat Software Home Page (EFS Software)