CVE-2005-2036 describes a vulnerability in Cool Cafe Chat version 1.2.1, where the modifyUser.asp script allows remote, unauthenticated attackers to retrieve the administrator's password and email address by manipulating the nickname value. This vulnerability has a CVSS score of 7.5 (High), indicating a low attack complexity and no authentication required, leading to potential compromise of confidentiality, integrity, and availability. While the vulnerability is old and has no known active exploits, public exploit code, or community discussion, its high severity means it could still pose a risk if unpatched in legacy systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.1CPE matchmatch criteria | cpe:2.3:a:cool_cafe_chat:cool_cafe_chat:1.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.