Record summary

CVE-2017-9557 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBEFS Easy Chat Server 3.1 - Password DisclosureExploitDB exploitby Aitezaz MohsinNot analyzed1 file
ExploitDB

PoC details

References

2