>> 123 Flash Chat Server Username Remote Directory Traversal Vulnerability
Title : 123 Flash Chat Server Username Remote Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2006-0198 CVE ID : CVE-2006-0223
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-01-16
Technical Description
A vulnerability has been identified in 123 Flash Chat Server, which may be exploited by remote attackers to create/overwrite arbitrary files and execute arbitrary commands. This flaw is due to an input validation error in the registration system that does not properly validate the "username" field, which may be exploited by remote attackers to create and execute malicious scripts with privileges of the server.