CVE-2014-5276 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php.

Reference

http://archives.neohapsis.com/archives/bugtraq/2014-08/0026.html http://packetstormsecurity.com/files/127775/Pro-Chat-Rooms-8.2.0-XSS-Shell-Upload-SQL-Injection.html http://www.exploit-db.com/exploits/34275 https://exchange.xforce.ibmcloud.com/vulnerabilities/95125 https://exchange.xforce.ibmcloud.com/vulnerabilities/95126

Share on: