PT-2005-3317 · Realchat · Realchat

Publicado

2005-07-27

·

Atualizado

2017-07-11

·

CVE-2005-2403

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions RealChat version 3.5.1b
Description The issue concerns the login protocol, which lacks authentication. This allows remote attackers to log on as other users by sniffing the beginning of a chat session and replaying it via a modified username.
Recommendations For RealChat version 3.5.1b, consider implementing authentication in the login protocol to prevent unauthorized access. As a temporary workaround, restrict access to sensitive features that rely on the login protocol until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2403

Produtos afetados

Realchat