vendor:
Easy Chat Server
by:
NetJackal
5.5
CVSS
MEDIUM
Remote Denial of Service (DoS)
400
CWE
Product Name: Easy Chat Server
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
2007
Easy Chat Server Remote DoS Exploit
Easy Chat Server has a built-in web server that allows users to log in. The login page has a maximum character limit of 30 for the Name and Password fields. If an attacker inserts a long Name and Password by editing or creating their own login page, the chat server will crash.
Mitigation:
Upgrade to a version that has fixed this vulnerability. Limit the character length allowed for Name and Password fields.