First published: Mon Jan 16 2006(Updated: )
Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
123 Flash Chat Server | =5.1 | |
123 Flash Chat Server | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0223 has a high severity rating due to its ability to allow unauthorized file access on the server.
To fix CVE-2006-0223, upgrade to the latest version of 123 Flash Chat Server that has patched this vulnerability.
CVE-2006-0223 affects users of Shanghai TopCMM 123 Flash Chat Server version 5.1 and 5.0.
An attacker can exploit CVE-2006-0223 to perform a directory traversal attack, allowing them to create or overwrite files on the server.
Symptoms of CVE-2006-0223 exploitation may include unauthorized file modifications or the presence of unexpected files on the server.