Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ch0P83

#34772of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2009-2268
7.5
2009-05-07
Flashchat · Flashchat · CVE-2008-6799
Name of the Vulnerable Software and Affected Versions: FlashChat version 5.0.8 Description: The issue allows remote attackers to bypass the role filter mechanism and gain administrative privileges. This is achieved by setting the `s` parameter to "7" in connection.php. Recommendations: For FlashChat version 5.0.8, consider restricting access to the connection.php file or validating the `s` parameter to prevent unauthorized privilege escalation. As a temporary workaround, restrict the use of the `s` parameter to minimize the risk of exploitation.