Lucene search

K
cveMitreCVE-2008-6502
HistoryMar 20, 2009 - 6:30 p.m.

CVE-2008-6502

2009-03-2018:30:00
CWE-22
mitre
web.nvd.nist.gov
30
cve-2008-6502
pro chat rooms
directory traversal
vulnerability
authenticated users
php script
avatar
csrf
xss

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

61.9%

Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a … (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (CSRF), cross-site scripting (XSS), or other impacts.

Affected configurations

Nvd
Node
prochatroomspro_chat_roomsMatch3.0.2
VendorProductVersionCPE
prochatroomspro_chat_rooms3.0.2cpe:2.3:a:prochatrooms:pro_chat_rooms:3.0.2:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

61.9%

Related for CVE-2008-6502