CVE-2005-2403 Information

Description

The login protocol in RealChat 3.5.1b does not use authentication which allows remote attackers to log on as other users by sniffing the beginning of a chat session and replaying it via a modified username.

Reference

http://seclists.org/lists/bugtraq/2005/Jul/0403.html http://securitytracker.com/id?1014562 http://www.securityfocus.com/bid/14358 https://exchange.xforce.ibmcloud.com/vulnerabilities/21497

Share on: