Record summary

CVE-2007-1896 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.

Description

Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a my_ms[root] cookie.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMySpeach 3.0.7 - Local/Remote File InclusionExploitDB exploitby Xst3nZNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

6