The login protocol in RealChat 3.5.1b does not use authentication, which allows remote attackers to log on as other users by sniffing the beginning of a chat session and replaying it via a modified username.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Realchat | Realchat | 3.5.1b (including) | 3.5.1b (including) |