Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2717 Path Traversal vulnerability in PHP Heaven PHPmychat 0.14.5
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a ..
network
high complexity
php-heaven CWE-22
2.6
2004-12-31 CVE-2004-2716 SQL Injection vulnerability in PHP Heaven PHPmychat 0.14.5
Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.
network
low complexity
php-heaven CWE-89
7.5
2004-12-31 CVE-2004-2715 Improper Authentication vulnerability in PHP Heaven PHPmychat 0.14.5
edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.
network
low complexity
php-heaven CWE-287
7.5
2004-12-31 CVE-2004-2714 USE of Externally-Controlled Format String vulnerability in Windowmaker
Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format string specifiers in a font specification in WMGLOBAL, probably a format string vulnerability.
6.0
2004-12-31 CVE-2004-2712 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Phrozensmoke Gyach Enhanced
Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data."
network
low complexity
phrozensmoke CWE-119
5.0
2004-12-31 CVE-2004-2711 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Phrozensmoke Gyach Enhanced
Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retrieval."
network
low complexity
phrozensmoke CWE-119
7.5
2004-12-31 CVE-2004-2710 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Phrozensmoke Gyach Enhanced
Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending certain typing statuses or (2) setting the chat room status bar to the current chat room name.
network
low complexity
phrozensmoke CWE-119
7.5
2004-12-31 CVE-2004-2709 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Phrozensmoke Gyach Enhanced
Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors involving HTML tags.
network
low complexity
phrozensmoke CWE-119
7.5
2004-12-31 CVE-2004-2708 Credentials Management vulnerability in Phrozensmoke Gyach Enhanced
Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.
network
low complexity
phrozensmoke CWE-255
5.0
2004-12-31 CVE-2004-2707 Undisclosed vulnerability in GYach Enhanced
Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors related to "several security flaws," probably related to buffer overflows in HTTP server responses.
network
low complexity
phrozensmoke
7.5