5.5
CVSSv2

CVE-2006-1963

Published: 21/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in main.php in PCPIN Chat 5.0.4 and previous versions allows remote authenticated users to include and execute arbitrary PHP code via a ".." (dot dot) in a language cookie, as demonstrated by uploading then accessing a smiliefile image that actually contains PHP code.

Vulnerable Product Search on Vulmon Subscribe to Product

pcpin pcpin chat 3.1.7r

pcpin pcpin chat 3.2.0

pcpin pcpin chat 5.0.1

pcpin pcpin chat 5.0.2

pcpin pcpin chat 3.1.5

pcpin pcpin chat 3.1.6

pcpin pcpin chat 5.0.3

pcpin pcpin chat 5.0.4

pcpin pcpin chat 3.2.1

pcpin pcpin chat 3.2.3

pcpin pcpin chat 4.0