7.5
CVSSv2

CVE-2004-2716

Published: 31/12/2004 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote malicious users to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

php heaven phpmychat 0.14.5

Exploits

source: wwwsecurityfocuscom/bid/10556/info phpHeaven phpMyChat is reported prone to multiple vulnerabilities The issues result from insufficient sanitization of user-supplied data and design flaws The following specific issues can affect the application: phpMyChat is prone to a HTML injection vulnerability The issue affects the 'input ...