nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-9557 CVE-2017-9557
HIGH
EFS Easy Chat Server 3.1 - Password Disclosure
Record summary
CVE-2017-9557 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEFS Easy Chat Server 3.1 - Password DisclosureExploitDB exploitby Aitezaz MohsinNot analyzed1 file
References
242153exploit
https://www.exploit-db.com/exploits/42153