PT-2009-2516 · Natterchat · Natterchat

Mountassif Moad

·

Published

2009-08-24

·

Updated

2017-09-29

·

CVE-2008-7047

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NatterChat version 1.1
Description The issue allows remote attackers to bypass authentication and gain administrator privileges. This can be achieved by making a direct request to the "admin/home.asp" endpoint. As a result, attackers can read or delete rooms and messages.
Recommendations For NatterChat version 1.1, consider restricting access to the "admin/home.asp" endpoint until a patch is available. Additionally, review the authentication mechanism to prevent unauthorized access.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7047

Affected Products

Natterchat