6.5
CVSSv2

CVE-2014-5275

Published: 20/10/2014 Updated: 08/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

prochatrooms text chat rooms 8.2.0

Exploits

# Exploit Title: Pro Chat Rooms v820 - Multiple Vulnerabilities # Google Dork: intitle:"Powered by Pro Chat Rooms" # Date: 5 August 2014 # Exploit Author: Mike Manzotti @ Dionach Ltd # Vendor Homepage: prochatroomscom # Software Link: prochatroomscom/softwarephp # Version: v820 # Tested on: Debian (Apache+MySQL) 1) Stored XSS ...