7.5
CVSSv2

CVE-2008-7049

Published: 24/08/2009 Updated: 21/11/2024

Vulnerability Summary

Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote malicious users to execute arbitrary SQL commands via the (1) txtUsername parameter (aka Username) and (2) txtPassword parameter (aka Password) in a form generated by home.asp. NOTE: due to lack of details, it is not clear whether this is related to CVE-2004-2206.

Vulnerable Product Search on Vulmon Subscribe to Product

natterchat natterchat 1.1

natterchat natterchat 1.12

Exploits

[+] Script Name : NATTERCHAT v11 remote login bypass [+] Author : Bl@ckbe@rD ('Tunisian TerrorisT') [+] Contact : blackbeard-sql[AT]hotmail{}fr ; [+] Dork : Powered by NATTERCHAT v 11 --//--> [+] Expl0iT : 1) Go to the Login page wwwexempleff/chat/nattechat/homeasp 2) Username : admin ...
[+] Script Name : Natterchat v112 (Auth Bypass) Remote SQL Injection Vulnerability [+] Author : Mountassif Moad [+] Dork : Powered by Natterchat v112 [+] Expl0iT : 1) Go to the Login page wwwsiteil/chat/nattechat/homeasp 2) Username : admin Password : ' or '1'='1 Live Demo wwwsprqca/cgi-bin/natte ...