CVE-2005-0862
EXPLOITEDPHPOpenChat <= 3.0.1 - Remote File Inclusion via phpbb_root_path Parameter
Title source: llmExploitation Summary
CVE-2005-0862 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including Albania Security Clan.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in PHPOpenChat 3.0.1 and prior versions. By manipulating the 'phpbb_root_path' parameter, an attacker can execute arbitrary server-side script code with the privileges of the webserver process.
Description
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.
Exploits (3)
This exploit demonstrates a remote file inclusion vulnerability in PHPOpenChat 3.0.1 and prior versions. By manipulating the 'phpbb_root_path' parameter, an attacker can execute arbitrary server-side script code with the privileges of the webserver process.
This exploit demonstrates a remote file inclusion vulnerability in PHPOpenChat 3.0.1 and prior versions. It allows an attacker to execute arbitrary server-side script code by manipulating the 'poc_root_path' or 'sourcedir' parameters to include a remote file with malicious commands.
This exploit demonstrates a remote file inclusion vulnerability in PHPOpenChat 3.0.1 and prior versions. By manipulating the `poc_root_path` parameter, an attacker can execute arbitrary commands on the server with the privileges of the webserver process.