VYPR

Sci Photo Chat

by Simm Comm

CVEs (2)

  • CVE-2008-1169Mar 5, 2008
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in the embedded HTTP server in SCI Photo Chat Server 3.4.9 and earlier allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot forward slash) in the GET command.

  • CVE-2004-0673Aug 6, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.