Vulnerabilities > CVE-2007-2939 - Remote File Include vulnerability in Mazens PHP Chat Mazens PHP Chat 3.0.0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
mazens-php-chat
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.

Vulnerable Configurations

Part Description Count
Application
Mazens_Php_Chat
1

Exploit-Db

descriptionMazens PHP Chat V3 (basepath) Remote File Inclusion Vulnerabilities. CVE-2007-2939. Webapps exploit for php platform
fileexploits/php/webapps/3994.txt
idEDB-ID:3994
last seen2016-01-31
modified2007-05-26
platformphp
port
published2007-05-26
reporterThE TiGeR
sourcehttps://www.exploit-db.com/download/3994/
titleMazens PHP Chat V3 basepath - Remote File Inclusion Vulnerabilities
typewebapps