exploit-db-mirror/exploits/php/webapps/22715.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

9 lines
No EOL
592 B
Text

source: http://www.securityfocus.com/bid/7777/info
WebChat has been reported prone to a database username disclosure weakness.
The issue presents itself when a malicious request is made for the WebChat ?users.php? page. An attacker may pass a guessed username as a specific URI parameter to the affected page. An attacker may exploit this weakness to enumerate database passwords.
This weakness was reported to affect WebChat version 2.0 other versions may also be affected.
http://www.example.com/modules/WebChat/users.php?rid=Non_Numeric&uid=-1&username=[Any_Word_or_your_code]