| Title |
123 Flash Chat Remote Code Injection Weakness |
| Published |
2006-01-24-12:00AM |
| Updated |
2006-01-25-10:34PM |
| Class |
Input Validation Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
Discovered by Jesus Olmos Gonzalez. |
| Vulnerable |
TopCMM Computing 123 Flash Chat Server 5.1
TopCMM Computing 123 Flash Chat Server 5.0 |
| Not Vulnerable |
TopCMM Computing 123 Flash Chat Server 5.1 _2 |
| Code |
The following string may be supplied as a username to gain administrative privileges: x;user.name= a;user.name=ADMIN_AVATAR_NAME; Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: content@securitydot.net
|
| TXT |
 |