Prochatrooms Pro Chat Rooms vulnerabilities
2 known vulnerabilities affecting prochatrooms/pro_chat_rooms.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2008-6502P4MEDIUMCVSS 4.6PoCv3.0.22009-03-20
CVE-2008-6502 [MEDIUM] CWE-22 CVE-2008-6502: Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to selec
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (
nvd
CVE-2008-6501P4MEDIUMCVSS 4.3PoCv3.0.22009-03-20
CVE-2008-6501 [MEDIUM] CWE-79 CVE-2008-6501: Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote
Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter.
nvd