First published: Wed Jan 25 2006(Updated: )
Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
123 Flash Chat Server | =5.0 | |
123 Flash Chat Server | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0418 is considered a critical vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2006-0418, upgrade to a patched version of the 123 Flash Chat Server, specifically version 5.2 or later.
CVE-2006-0418 affects versions 5.0 and 5.1 of the 123 Flash Chat Server.
CVE-2006-0418 is categorized as an eval injection vulnerability allowing the execution of arbitrary code.
Attackers with access to the username input field can exploit CVE-2006-0418 to execute arbitrary code.