phpMyChat Connected_Users.Lib.PHP3 Local File Include Vulnerability
BID:20219
Info
phpMyChat Connected_Users.Lib.PHP3 Local File Include Vulnerability
| Bugtraq ID: | 20219 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5088 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2006 12:00AM |
| Updated: | Mar 24 2008 08:20PM |
| Credit: | SolpotCrew is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpHeaven phpMyChat 0.14.5 phpHeaven phpMyChat 0.1 |
| Not Vulnerable: | |
Discussion
phpMyChat Connected_Users.Lib.PHP3 Local File Include Vulnerability
phpMyChat is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit may allow an unauthorized user to view files and to execute local scripts.
This issue affects phpMyChat 0.1; other versions may also be affected.
phpMyChat is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit may allow an unauthorized user to view files and to execute local scripts.
This issue affects phpMyChat 0.1; other versions may also be affected.
Exploit / POC
phpMyChat Connected_Users.Lib.PHP3 Local File Include Vulnerability
Attackers may launch attacks through a browser.
Attackers may launch attacks through a browser.
Solution / Fix
phpMyChat Connected_Users.Lib.PHP3 Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
phpMyChat Connected_Users.Lib.PHP3 Local File Include Vulnerability
References:
References:
- phpMyChat Homepage (phpHeaven)
- SolpotCrew Advisory #13 - phpMyChat 0.1 (ChatPath) Remote File Inclusion (SolpotCrew)