发布时间 :2001-02-07 00:00:00
修订时间 :2008-09-05 16:26:20

[原文]Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.


        phpMyChat 0.14.5版本之前版本的多个漏洞存在于带有未知后果的(1)input.php3,(2)handle_inputH.php3,或(3)index.lib.php3,该漏洞可能与用户欺骗或不当初始化变量有关。

- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

        Upgrade to the latest version of the software (version 0.14.5 or higher).
phpMyChat contains a flaw related to the 'input.php3' script that may allow a remote attacker to inject arbitrary SQL queries or to conduct a remote cross site scripting attack. No further details have been provided.

2001-07-02 Unknow
Unknow Unknow

Upgrade to version 0.14.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Unknown or Incomplete

Alexei Shain is credited for this issue.

Nicholas Hoizey phpMyChat 0.14.5

Nicholas Hoizey phpMyChat 0.14.5

The phpMyChat script named 'handle_inputH.php3' is prone to SQL injection attacks.

Version 0.14.4 is known to be affected. Earlier versions may also be affected.

There is no further information about this vulnerability.

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: <>.

Upgrade the affected application to a non-vulnerable version (version 0.14.5 or higher).

