// For flags

CVE-2008-7210

AJchat 0.10 - 'unse' SQL Injection

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET["s"] variable from being unset. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in AJChat.

directory.php in AJchat 0.10 permite a atacantes remotos saltarse la validación de entrada y conducir ataques de inyección SQL a través de un parámetro numérico con un valor que coincida con el valor hash del parámetro s, lo que previene la variable asociada $_GET["s"] de no ser fijada. NOTA Se podría argumentar que esta vulnerabilidad se debe a un error en el comando PHP unset (CVE-2006-3017) y la corrección adecuada debería ser en PHP, y si es así, entonces esto no debería ser tratado como una vulnerabilidad en ajchat.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-09-11 CVE Reserved
  • 2009-09-11 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ming Han
Search vendor "Ming Han"
Ajchat
Search vendor "Ming Han" for product "Ajchat"
0.10
Search vendor "Ming Han" for product "Ajchat" and version "0.10"
-
Affected