MOHA Chat 0.1b7 and earlier does not require authentication for use of the plug in API, which has unknown impact and attack vectors.
Link | Tags |
---|---|
http://mohachat.sourceforge.net/download/release_notes/#0.1b8 | patch |
http://www.vupen.com/english/advisories/2007/0599 | vdb entry |
http://osvdb.org/31934 | vdb entry |