Vulnerabilities > CVE-2006-5837 - Remote Code Execution vulnerability in Simplechat 1.0.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
simplechat
exploit available

Summary

Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows remote attackers to inject arbitrary PHP code into chat_log.php via the msg parameter.

Vulnerable Configurations

Part Description Count
Application
Simplechat
1

Exploit-Db

descriptioniWare Pro <= 5.0.4 (chat_panel.php) Remote Code Execution Vulnerability. CVE-2006-5837. Webapps exploit for php platform
fileexploits/php/webapps/2733.txt
idEDB-ID:2733
last seen2016-01-31
modified2006-11-07
platformphp
port
published2006-11-07
reporternuffsaid
sourcehttps://www.exploit-db.com/download/2733/
titleiWare Pro <= 5.0.4 chat_panel.php Remote Code Execution Vulnerability
typewebapps