CVE-2008-1504
- EPSS 0.24%
- Veröffentlicht 25.03.2008 19:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in setup.php3 in phpHeaven phpMyChat 0.14.5 allows remote attackers to inject arbitrary web script or HTML via the Lang parameter. NOTE: the provenance of this information is unknown; the details are obtained...
- EPSS 0.23%
- Veröffentlicht 15.11.2006 15:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in localization/languages.lib.php3 in PhpMyChat 0.14.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ChatPath parameter.
CVE-2006-5088
- EPSS 1.09%
- Veröffentlicht 29.09.2006 20:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP remote file inclusion vulnerability in connected_users.lib.php3 in phpHeaven phpMyChat 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ChatPath parameter.
CVE-2006-1669
- EPSS 0.94%
- Veröffentlicht 07.04.2006 10:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL injection vulnerability in chat/messagesL.php3 in phpHeaven Team PHPMyChat 0.14.5 and earlier allows remote attackers to execute arbitrary SQL commands via the T parameter. NOTE: this issue can be leveraged to execute arbitrary shell commands si...
CVE-2005-3991
- EPSS 1.4%
- Veröffentlicht 04.12.2005 23:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium parameter to (1) start_page.css.php and (2) style.css.php; or the From parameter to users_popupL.php.
CVE-2005-1619
- EPSS 3.99%
- Veröffentlicht 16.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOT...
CVE-2001-1357
- EPSS 0.47%
- Veröffentlicht 07.02.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.
CVE-2001-1358
- EPSS 0.21%
- Veröffentlicht 07.02.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.