Record summary

CVE-2007-1895 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMySpeach 3.0.7 - Local/Remote File InclusionExploitDB exploitby Xst3nZNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

5