|Title:||SimpleChat information disclosure|
It is possible to retrieve list of users currently connected to
the remote SimpleChat server by requesting the file data/usr.
An attacker may use this flaw to obtain the IP address of every
user currently connected and possibly harass them directly.
Solution : None at this time. Add a .htaccess file to prevent an attacker
from obtaining this file
Risk factor : Low
BugTraq ID: 7168|
|Copyright||This script is Copyright (C) 2003 Renaud Deraison|
|This is only one of 93608 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.