register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.
References
Link | Resource |
---|---|
https://www.exploit-db.com/exploits/42153/ | Exploit Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:23:09
Updated: 2022-10-03T16:23:09
Reserved: 2022-10-03T00:00:00
Link: CVE-2017-9557
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-06-12T15:29:00.160
Modified: 2021-03-26T17:56:51.507
Link: CVE-2017-9557
JSON object: View
Redhat Information
No data.
CWE