1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




FlashChat "s" Security Bypass

Report ID: SA32350
Source: Secunia
Date of Discovery: 22.10.2008
Criticality: Low
Affects:
FlashChat 5.x

Compromise From: From remote
Compromise Type: Security bypass

Summary

A vulnerability in FlashChat, which can be exploited by malicious users to bypass certain security restrictions.

Detailed Description

A vulnerability in FlashChat, which can be exploited by malicious users to bypass certain security restrictions.

The application allows access to administrative functionality by checking if a certain parameter is set. This can be exploited to perform administrative operations by setting the parameter "s" to the value "7".

This vulnerability is confirmed in version 5.0.8. Other versions may also be affected.

Solution

Ensure that proper access restrictions are implemented.