Vulnerabilities > CVE-2006-6995 - Input Validation vulnerability in V3 Chat Instant Messenger

047910
CVSS 6.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
v3-chat
exploit available

Summary

mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername parameter. The attacker must already be authenticated on V3Chat.

Vulnerable Configurations

Part Description Count
Application
V3_Chat
1

Exploit-Db

descriptionV3 Chat Instant Messenger mycontacts.php membername Arbitrary User Buddy List Manipulation. CVE-2006-6995. Webapps exploit for php platform
idEDB-ID:28075
last seen2016-02-03
modified2006-06-20
published2006-06-20
reporterLuny
sourcehttps://www.exploit-db.com/download/28075/
titleV3 Chat Instant Messenger - mycontacts.php membername Arbitrary User Buddy List Manipulation