Vulnerabilities > CVE-2007-0485 - Unspecified vulnerability in Webchat.Org Webchat 0.77
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | WebChat 0.77 (defines.php WEBCHATPATH) Remote File Include Vuln. CVE-2007-0485. Webapps exploit for php platform |
file | exploits/php/webapps/3169.txt |
id | EDB-ID:3169 |
last seen | 2016-01-31 |
modified | 2007-01-21 |
platform | php |
port | |
published | 2007-01-21 |
reporter | v1per-haCker |
source | https://www.exploit-db.com/download/3169/ |
title | WebChat 0.77 defines.php WEBCHATPATH Remote File Include Vuln |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | WEBCHAT_CODE_INJECTION.NASL |
description | The version of Webchat installed on the remote host allows an attacker to read local files or execute PHP code, possibly taken from third- party sites, subject to the permissions of the web server user id. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11315 |
published | 2003-03-03 |
reporter | This script is Copyright (C) 2003-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/11315 |
title | WebChat defines.php WEBCHATPATH Parameter Remote File Inclusion |
code |
|
References
- http://secunia.com/advisories/8206
- http://secunia.com/advisories/8206
- http://www.securityfocus.com/archive/1/313610/30/25700/threaded
- http://www.securityfocus.com/archive/1/313610/30/25700/threaded
- http://www.securityfocus.com/bid/7000
- http://www.securityfocus.com/bid/7000
- http://www.securitytracker.com/id?1006193
- http://www.securitytracker.com/id?1006193
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31624
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31624
- https://www.exploit-db.com/exploits/3169
- https://www.exploit-db.com/exploits/3169