PT-2005-1576 · Chat Anywhere · Chat Anywhere

Published

2005-02-23

·

Updated

2008-09-05

·

CVE-2005-0522

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chat Anywhere version 2.72a
Description The issue allows local users to gain privileges by accessing sensitive information stored in plaintext in the .INI file for a chatroom. This includes passwords.
Recommendations For version 2.72a, consider encrypting or securely storing sensitive information, such as passwords, to prevent unauthorized access. As a temporary workaround, restrict access to the .INI file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0522

Affected Products

Chat Anywhere