Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-9543. PoCs published by Aitezaz Mohsin.
AI-analyzed exploit summary This exploit demonstrates a pre-authentication remote password reset vulnerability in Easy Chat Server by sending a crafted HTTP POST request to the registration endpoint. It allows an attacker to change any user's password without authentication.
Description
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.
Exploits (1)
This exploit demonstrates a pre-authentication remote password reset vulnerability in Easy Chat Server by sending a crafted HTTP POST request to the registration endpoint. It allows an attacker to change any user's password without authentication.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N