PT-2002-3103 · Xoops+1 · Xoops+1

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2391

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WebChat version 1.5 XOOPS version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands via the roomid parameter in the "index.php" file of WebChat.
Recommendations For WebChat version 1.5, avoid using the roomid parameter in the affected API endpoint until the issue is resolved. For XOOPS version 1.0, restrict access to the vulnerable WebChat module to minimize the risk of exploitation.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2002-2391

Affected Products

Wechat
Xoops