6.8
CVSSv2

CVE-2007-1895

Published: 09/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and previous versions, when used with PHP 5, allows remote malicious users to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630.

Vulnerable Product Search on Vulmon Subscribe to Product

sky gunning myspeach

Exploits

/=======================================\ | Advisory :: MySpeach <= 307 | +=======================================+---------------------------------------------------------------\ | | | Download link : wwwgraphiksnet/scripts-php/script-7-1-0html | | Official website : wwwgraphiksnet | | ...