• Forum
  • Doc
  • Screenshots
  • Download
  • Donate
  • Contributors
  • Contact
  • Follow @phpfreechat
  • DEMO
  • Board index ‹ Version 1.x branch ‹ General Support (v1.x)
  • Change font size
  • FAQ
  • Register
  • Login

Secunia Advisory SA42437 - phpFreeChat \"cmd\" Cross-Site Sc

Moderators: OldWolf, re*s.t.a.r.s.*2

Post a reply
4 posts • Page 1 of 1

Postby belzecue » Sat Feb 05, 2011 10:38 am

http://secunia.com/advisories/42437/

phpFreeChat "cmd" Cross-Site Scripting Vulnerability
Secunia Advisory SA42437
Get alerted and manage the vulnerability life cycle
Free Trial

Release Date 2010-12-10

Popularity 343 views
Comments 0 comments

Criticality level Less criticalLess critical
Impact Cross Site Scripting
Where From remote
Authentication level Available in Customer Area

Report reliability Available in Customer Area
Solution Status Unpatched

Systems affected Available in Customer Area
Approve distribution Available in Customer Area

Software:
phpFreeChat 1.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.



Description

A vulnerability has been discovered in phpFreeChat, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed via the "cmd" parameter to index.php (when "pfc_ajax" is set and "f" is set to "handleRequest") is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability is confirmed in version 1.3. Other versions may also be affected.

Solution
Edit the source code to ensure that input is properly sanitised.

Provided and/or discovered by
Zsolt Imre
belzecue
New member
 
Posts: 1
Joined: Sat Feb 05, 2011 10:35 am
Top

Postby siwula » Wed Feb 09, 2011 1:34 pm

So, where is patch? How to patch temporary?
siwula
Member
 
Posts: 10
Joined: Sun Oct 10, 2010 3:43 pm
Top

Postby kathlenrt » Fri Mar 25, 2011 10:39 pm

siwula wrote:So, where is patch? How to patch temporary?

I also have the same question.


how to cure diarrhea
back ache
how to get rid of bronchitis
do it yourself carpet cleaning
Last edited by kathlenrt on Sun Apr 24, 2011 8:05 am, edited 1 time in total.
kathlenrt
New member
 
Posts: 2
Joined: Fri Mar 25, 2011 10:35 pm
Top

Postby re*s.t.a.r.s.*2 » Fri Mar 25, 2011 11:22 pm

The creator Kerphi have checked the code and find out no issue with the current version PHPFREECHAT 1.3

regards.
Free Singles Chat Rooms No Registration Required
Text and Chat Singles no need to register or app required
Sala De Bate Papo Online Grátis E Sem Cadastro
re*s.t.a.r.s.*2
Support Team
 
Posts: 612
Joined: Wed Sep 24, 2008 4:04 pm
Location: los angeles CA
  • Website
Top


Post a reply
4 posts • Page 1 of 1

Return to General Support (v1.x)

Who is online

Users browsing this forum: No registered users and 17 guests

  • Board index
  • The team • Delete all board cookies • All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
Sign in
Wrong credentials
Sign up I forgot my password
.
jeu-gratuit.net | more partners
Fork me on GitHub