Back to search
CVE-2008-1171
Published: Mar 5, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) 123flashchat.php and (2) phpbb_login_chat.php. NOTE: CVE disputes this issue because $phpbb_root_path is explicitly set to "./" in both programs
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20080228 123 Flash Chat Module for phpBB
mailing-list
x_refsource_BUGTRAQ
20080305 false: 123 Flash Chat RFI
mailing-list
x_refsource_VIM
20080228 Re: 123 Flash Chat Module for phpBB
mailing-list
x_refsource_BUGTRAQ
3716
third-party-advisory
x_refsource_SREASON
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now