PT-2006-3538 · Dschat · Dschat

Published

2006-05-25

·

Updated

2017-07-20

·

CVE-2006-2592

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DSChat version 1.0
Description The issue allows remote attackers to execute arbitrary PHP code via the Nickname field. This field is not sanitized before creating a file in a user directory.
Recommendations For DSChat version 1.0, consider sanitizing the Nickname field to prevent the execution of arbitrary PHP code. As a temporary workaround, restrict access to the file creation functionality in user directories until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2592

Affected Products

Dschat