CVE-2004-2466
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 75%
from disclosure to weapon1812 days
Published on NVDAug 20
1st PoC+1812d
metasploit+724d
exploitation probability
75%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.
Affected products
n/a · n/apublic PoCs found — 6✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16772exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/33326cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/4289exploitdbwww.exploit-db.com/exploits/50999unverifiedcve_referencepacketstormsecurity.com/files/167892/Easy-Chat-Server-3.1-Buffer-Overflow.htmlunverifiedcve_referencewww.exploit-db.com/exploits/33326unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2004-07/0013.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2004-07/0077.htmlhttp://packetstormsecurity.com/files/167892/Easy-Chat-Server-3.1-Buffer-Overflow.htmlhttp://secunia.com/advisories/12006http://secunia.com/advisories/26461http://secunia.com/advisories/58427https://exchange.xforce.ibmcloud.com/vulnerabilities/16629https://exchange.xforce.ibmcloud.com/vulnerabilities/36013https://www.exploit-db.com/exploits/4289http://www.autistici.org/fdonato/advisory/EasyChatServer1.2-adv.txthttp://www.exploit-db.com/exploits/33326http://www.osvdb.org/7416