Description
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.
Problem types
Improper Verification of Source of a Communication Channel
Product status
Credits
Miguel Mendez Z
References
www.exploit-db.com/exploits/46806 (ExploitDB-46806)
www.echatserver.com (Official Product Homepage)
www.echatserver.com/ecssetup.exe (Product Reference)
www.vulncheck.com/...denial-of-service-via-message-parameter (VulnCheck Advisory: Easy Chat Server 3.1 Denial of Service via message Parameter)