Flashchat · Flashchat · CVE-2008-6799
Name of the Vulnerable Software and Affected Versions:
FlashChat version 5.0.8
Description:
The issue allows remote attackers to bypass the role filter mechanism and gain administrative privileges. This is achieved by setting the `s` parameter to "7" in connection.php.
Recommendations:
For FlashChat version 5.0.8, consider restricting access to the connection.php file or validating the `s` parameter to prevent unauthorized privilege escalation. As a temporary workaround, restrict the use of the `s` parameter to minimize the risk of exploitation.