6.8
CVSSv2

CVE-2012-6047

Published: 27/11/2012 Updated: 27/11/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and previous versions allows remote malicious users to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page in an adminpanel action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

x7 group x7 chat 1.3.6

x7 group x7 chat 1.3.5b

x7 group x7 chat 1.3.4b

x7 group x7 chat 1.3.3b

x7 group x7 chat

x7 group x7 chat 1.1.1b

x7 group x7 chat 1.0.0b

x7 group x7 chat 2.0.3

x7 group x7 chat 2.0.0

x7 group x7 chat 1.3.2b

x7 group x7 chat 1.3.0b

x7 group x7 chat 1.1.2b

x7 group x7 chat 2.0.4.4

x7 group x7 chat 2.0.2

x7 group x7 chat 1.3.1b

x7 group x7 chat 1.2.0b

Exploits

# Exploit Title: X7 Chat 2051 CSRF Add Admin Exploit # Google Dork: intitle:"Chat Room" "Powered By X7 Chat 205" # Date: 09052012 # Author: DennSpec # Software Link: x7chatcom/releases/v2/x7chat2_0_5_1zip # Version: <= 2051 firstly, register and give a username (framehtml in path of your main html page) <html> & ...