Babo Violent 2 2.08.00 does not validate the sender field of a chat message composed by a client, which allows remote authenticated users to spoof messages.
Link | Tags |
---|---|
http://securityreason.com/securityalert/3024 | third party advisory |
http://www.securityfocus.com/archive/1/476520/100/0/threaded | mailing list |
http://aluigi.altervista.org/adv/bv2x-adv.txt |