Vulnerability record · CVE-2004-2466 · published 31 December 2004
CVE-2004-2466: Easy Chat Server chat.ghp username buffer overflow denial of service
Efs Software · Easy Chat Server
Easy Chat Server 1.2 (and reportedly 2.2) mishandles an overly long username parameter in chat.ghp, causing a server crash that is possibly a buffer overflow. The flaw is remotely reachable without authentication, so an unauthenticated attacker can take the chat service down.
Description
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated denial of service with public exploit references and very high EPSS, but impact is limited to availability and the record is old with no confirmed code execution.
What it is
Easy Chat Server 1.2 (and reportedly 2.2) mishandles an overly long username parameter in chat.ghp, causing a server crash that is possibly a buffer overflow. The flaw is remotely reachable without authentication, so an unauthenticated attacker can take the chat service down.
Impact
An attacker can crash the chat server, causing a denial of service for all users. The record only describes a crash, so code execution is not confirmed.
Attack surface
Reached over the network via the chat.ghp endpoint by supplying a long username parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Public exploit and vendor advisory references exist, and EPSS is very high (0.74696, 99.5th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Patch or upgrade Easy Chat Server to a fixed release; if none is available, retire or isolate the product.
- Place the chat service behind a reverse proxy or WAF that rejects oversized username parameters.
- Restrict network access to the chat.ghp endpoint to trusted clients only.
- Monitor the service for crash/restart loops and treat repeated crashes as an attack indicator.
Detection
- Inspect HTTP requests to chat.ghp for abnormally long username parameter values.
- Alert on server crash or restart events correlated with inbound chat.ghp requests.
- Log and review source IPs sending oversized or malformed parameters to the chat service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-2466 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-2466), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.