Vulnerabilities > Phpfreechat > Phpfreechat > 1.1

DATE CVE VULNERABILITY TITLE RISK
2018-01-25 CVE-2018-5954 Resource Exhaustion vulnerability in PHPfreechat
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands.
network
low complexity
phpfreechat CWE-400
5.0
2008-07-31 CVE-2008-3428 Improper Authentication vulnerability in PHPfreechat 1.0/1.1
Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.
network
low complexity
phpfreechat CWE-287
6.5