Vendorsechatservereasy_chat_serverany version
Vulnerabilities

echatserver Easy Chat Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-9544
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code.
Published 2017-06-12 · Modified
9.8EPSS 0.241
CVE-2018-25221
EChat Server 3.1 Buffer Overflow via chat.ghp username Parameter
Published 2026-03-28 · Analyzed
9.8EPSS 0.008
CVE-2017-9557
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.
Published 2017-06-12 · Modified
7.5EPSS 0.017
CVE-2017-9543
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.
Published 2017-06-12 · Modified
7.5EPSS 0.013