PT-2004-1760 · Sci · Sci Photo Chat Server

Publicado

2004-07-13

·

Atualizado

2017-07-11

·

CVE-2004-0673

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SCI Photo Chat Server version 3.4.9
Description A cross-site scripting (XSS) issue allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message. This occurs when the server responds to an invalid request by including it in the error message, thus allowing the execution of malicious scripts.
Recommendations For SCI Photo Chat Server version 3.4.9, update to a newer version that addresses this issue, as using outdated software can pose significant security risks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0673

Produtos afetados

Sci Photo Chat Server