7.5
CVSSv2

CVE-2018-5979

Published: 24/01/2018 Updated: 07/02/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.

Vulnerable Product Search on Vulmon Subscribe to Product

wchat project wchat 1.5

Exploits

# # # # # # Exploit Title: Wchat - Fully Responsive PHP AJAX Chat Script 15 - SQL Injection # Dork: N/A # Date: 23012018 # Vendor Homepage: bylancercom/ # Software Link: codecanyonnet/item/wchat-fully-responsive-phpajax-chat/18047319 # Version: 15 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: CVE-2018-5979 # # ...
Wchat version 15 suffers from a remote SQL injection vulnerability ...