7.5
CVSSv2

CVE-2008-4718

Published: 23/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and previous versions allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in the help_file parameter, a different vector than CVE-2006-2156.

Vulnerable Product Search on Vulmon Subscribe to Product

x7 group x7 chat 1.3.5b

x7 group x7 chat 1.3.4b

x7 group x7 chat 1.1.1b

x7 group x7 chat 1.0.0b

x7 group x7 chat

x7 group x7 chat 1.3.1b

x7 group x7 chat 1.3.0b

x7 group x7 chat 2.0.0

x7 group x7 chat 1.3.6

x7 group x7 chat 1.2.0b

x7 group x7 chat 1.1.2b

x7 group x7 chat 1.3.3b

x7 group x7 chat 1.3.2b

Exploits

==================================================================== [o] X7 Chat <= 201A1 Local File Inclusion Vulnerability Software : X7 Chat version 2051 Vendor : x7chatcom/ Author : NoGe Contact : noge[dot]code[at]gmail[dot]com ============================================================== ...
------------------------------------------------------------------------- -- JIKI Team [ JIKO + KIl1er + merwan-neo ] --- ------------------------------------------------------------------------- # Author : jiko # email : jalikom@hotmailcom # Home : wwwno-exploitCom # Script : X7 Chat Version 201 # Bug : Local File In ...