vendor:
AJchat
by:
Eugene Minaev
9.3
CVSS
HIGH
AJchat Remote Sql Injection
89
CWE
Product Name: AJchat
Affected Version From: Prior to 2.0
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: cpe:a:ajchat:ajchat
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
AJchat Remote Sql Injection using unset() bug
AJchat is vulnerable to a remote SQL injection attack due to an unset() bug. An attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. This vulnerability affects AJchat versions prior to 2.0.
Mitigation:
Upgrade to AJchat version 2.0 or later.