20140805 Pro Chat Rooms v8.2.0 - Multiple Vulnerabilitiesmailing list
http://archives.neohapsis.com/archives/bugtraq/2014-08/0026.html CVE-2014-5276
Pro Chat Rooms 8.2.0 - Multiple Vulnerabilities
Record summary
CVE-2014-5276 has a selected CVSS score of 3.5; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPro Chat Rooms 8.2.0 - Multiple VulnerabilitiesExploitDB exploitby Mike ManzottiNot analyzed1 file
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/127775/Pro-Chat-Rooms-8.2.0-XSS-Shell-Upload-SQL-Injection.html 34275exploit
http://www.exploit-db.com/exploits/34275 prochatrooms-uploadedfile-xss(95125)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/95125 prochatrooms-profilesindex-xss(95126)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/95126 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-5276