vendor:
GTChat
by:
VTECin5th
7,5
CVSS
HIGH
User Creation Exploit
264
CWE
Product Name: GTChat
Affected Version From: GTChat .95
Affected Version To: GTChat .95
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
GTChat .95 User Creation Exploit
This exploit allows an attacker to create multiple users on GTChat .95. The attacker needs to provide the host, path to the chat directory, and the number of users to create. The script then creates the users with random usernames and passwords, and random emails. It does not verify whether or not the user is actually being created.
Mitigation:
Upgrade to GTChat .93 or later.