PT-2011-3668 · Unknown · A Really Simple Chat

Henri Salo

·

Published

2011-06-29

·

Updated

2011-06-30

·

CVE-2011-2181

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions A Really Simple Chat (ARSC) version 3.3-rc2
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the arsc user parameter to "base/admin/edit user.php", the arsc layout id parameter in "base/admin/edit layout.php", or the arsc room parameter to "base/admin/edit room.php".
Recommendations For A Really Simple Chat (ARSC) version 3.3-rc2, consider disabling access to the "base/admin/edit user.php", "base/admin/edit layout.php", and "base/admin/edit room.php" scripts until a patch is available. Avoid using the arsc user, arsc layout id, and arsc room parameters in the affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2181

Affected Products

A Really Simple Chat