Vulnerabilities > CVE-2005-0862 - Remote File Include vulnerability in PHPopenchat 2.3.4/3.0.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phpopenchat
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.

Vulnerable Configurations

Part Description Count
Application
Phpopenchat
2

Exploit-Db

  • descriptionPHPOpenChat 2.3.4/3.0.1 poc_loginform.php phpbb_root_path Parameter Remote File Inclusion. CVE-2005-0862. Webapps exploit for php platform
    idEDB-ID:25227
    last seen2016-02-03
    modified2005-03-15
    published2005-03-15
    reporterAlbania Security Clan
    sourcehttps://www.exploit-db.com/download/25227/
    titlePHPOpenChat 2.3.4/3.0.1 PoC_loginform.php phpbb_root_path Parameter Remote File Inclusion
  • descriptionPHPOpenChat 2.3.4/3.0.1 ENGLISH_poc.php Remote File Inclusion. CVE-2005-0862. Webapps exploit for php platform
    idEDB-ID:25229
    last seen2016-02-03
    modified2005-03-15
    published2005-03-15
    reporterAlbania Security Clan
    sourcehttps://www.exploit-db.com/download/25229/
    titlePHPOpenChat 2.3.4/3.0.1 ENGLISH_poc.php Remote File Inclusion