PT-2007-7165 · Phpmychat · Phpmychat

Published

2007-12-10

·

Updated

2018-10-15

·

CVE-2007-6296

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpMyChat version 0.14.5
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the From parameter in the users popupL.php3 file.
Recommendations For phpMyChat version 0.14.5, consider restricting access to the users popupL.php3 file or validating the From parameter to prevent remote file inclusion attacks. As a temporary workaround, avoid using the From parameter in the affected file until a patch is available.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6296

Affected Products

Phpmychat