phpfreechat records
3 published records for vendor phpfreechat.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2018-5954Proof of concept | phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands.phpfreechat · phpfreechat · CWE-400 | High7.5 | — | 8.9% | Jan 25, 2018 |
26Monitor | CVE-2008-3428No exploit | Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parametphpfreechat · phpfreechat · CWE-287 | Medium6.5 | — | 1.2% | Jul 31, 2008 |
20Monitor | CVE-2011-3777No exploit | phpFreeChat 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation phpfreechat · phpfreechat · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
- CVE-2018-595433Monitor
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands.
HighCVSS 7.5Proof of conceptEPSS 9%phpfreechat · phpfreechatJan 25, 2018
- CVE-2008-342826Monitor
Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id paramet
MediumCVSS 6.5No exploitEPSS 1%phpfreechat · phpfreechatJul 31, 2008
- CVE-2011-377720Monitor
phpFreeChat 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
MediumCVSS 5.0No exploitEPSS 1%phpfreechat · phpfreechatSep 23, 2011