EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-28 12:16
Updated : 2026-03-30 13:26
NVD link : CVE-2018-25221
Mitre link : CVE-2018-25221
CVE.ORG link : CVE-2018-25221
JSON object : View
Products Affected
No product.
CWE
CWE-787
Out-of-bounds Write
