Vulnerabilities (CVE)

Filtered by vendor Dschat Subscribe
Filtered by product Dschat
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2605 1 Dschat 1 Dschat 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatbox, probably involving the ctext parameter to send.php.
CVE-2006-2592 1 Dschat 1 Dschat 2024-02-04 7.5 HIGH N/A
Unspecified vulnerability in DSChat 1.0 allows remote attackers to execute arbitrary PHP code via the Nickname field, which is not sanitized before creating a file in a user directory. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.