CVE-2017-9557
Last modified
CVE-2017-9557 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Echatserver | Easy Chat Server | >= 2.0, <= 3.1 |
References
- https://www.exploit-db.com/exploits/42153/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42153/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9557?
How severe is CVE-2017-9557?
How do I fix CVE-2017-9557?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-9551Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16…
- CVE-2017-9552A design flaw in authentication in Synology Photo Station 6.…
- CVE-2017-9553A design flaw in SYNO.API.Encryption in Synology DiskStation…
- CVE-2017-9554An information exposure vulnerability in forget_passwd.cgi i…
- CVE-2017-9555Cross-site scripting (XSS) vulnerability in PixlrEditorHandl…
- CVE-2017-9556Cross-site scripting (XSS) vulnerability in Video Metadata E…
- CVE-2017-9558The wawa-employees-credit-union-mobile/id1158082793 app 4.0.…
- CVE-2017-9559The MEA Financial vision-bank/id420406345 app 3.0.1 for iOS …
- CVE-2017-9560The cayuga-lake-national-bank/id1151601539 app 4.0.1 for iOS…
- CVE-2017-9561The Lee Bank & Trust lbtc-mobile/id1068984753 app 3.0.1 for …
- CVE-2017-9562The Freedom First freedom-1st-credit-union-mobile-banking/id…
- CVE-2017-9563The First Citizens Community Bank fccb/id809930960 app 3.0.1…
Are you affected by CVE-2017-9557?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
