CVE-2007-6297
PHPMyChat 0.14.5 - Cross-Site Scripting via LIMIT, Link, LastCheck, or B Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-6297. PoCs published by beenudel1986.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpMyChat 0.14.5 by injecting malicious JavaScript via the LIMIT parameter in deluser.php3. The payload uses HTML entity encoding to bypass input sanitization and execute an alert dialog.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML via the (1) LIMIT parameter to chat/deluser.php3, the (2) Link parameter to chat/edituser.php3, or the (3) LastCheck or (4) B parameter to chat/users_popupL.php3. NOTE: the FontName vectors for start_page.css.php3 and style.css.php3 are already covered by CVE-2005-1619. The medium vectors for start_page.css.php3 (start_page.css.php) and style.css.php3 (style.css.php), and the From vector for users_popupL.php3 (users_popupL.php), are already covered by CVE-2005-3991.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpMyChat 0.14.5 by injecting malicious JavaScript via the LIMIT parameter in deluser.php3. The payload uses HTML entity encoding to bypass input sanitization and execute an alert dialog.
This exploit demonstrates multiple XSS vulnerabilities in phpMyChat 0.14.5 by injecting malicious scripts via unsanitized input parameters in the URL. The PoC includes payloads that trigger JavaScript alerts, confirming the vulnerability.