Multiple Vulnerabilities in phpHeaven phpMyChat
phpMyChat is prone to multiple vulnerabilities, including HTML injection, SQL injection, authentication bypass, and file disclosure. The HTML injection vulnerability allows an attacker to inject malicious HTML or script code into the affected application. The SQL injection vulnerabilities occur when SQL syntax is passed through the URI parameters of the 'usersL.php3' script. The authentication bypass vulnerability allows an attacker to bypass the authentication system by modifying the phpMyChat authentication screen. The file disclosure vulnerability allows an authenticated site administrator to disclose a target file by including a relative path with directory traversal sequences as a value for a URI parameter passed to the 'admin.php3' script.