Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

LionMax Software Chat Anywhere User IP Address Obfuscation Vulnerability

It has been reported that Chat Anywhere may be prone to a user IP address obfuscation vulnerability that may allow an attacker to hide their IP address from the administrator. The issue presents itself if an attacker uses '%00' characters at the beginning of their nickname. Due to this, it may not be possible to ban or remove abusive users from a chat room.

Chat Anywhere 2.72 and prior are reported to be affected by this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus