PT-2007-1315 · Andys · Andys Chat

Spc-X

·

Published

2007-02-23

·

Updated

2018-10-16

·

CVE-2006-7036

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Andys Chat version 4.5
Description A remote file inclusion issue in the register.php file allows remote attackers to execute arbitrary code via the action parameter. This issue was reported by a researcher, but its validity cannot be confirmed due to the vendor no longer distributing the product.
Recommendations For Andys Chat version 4.5, consider disabling the action parameter in the register.php file as a temporary workaround until a more permanent solution can be found. Restrict access to the register.php file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7036

Affected Products

Andys Chat