CVE-2007-2939
Mazen's PHP Chat 3.0.0 - Remote File Inclusion via basepath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2939. PoCs published by ThE TiGeR.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Mazen's PHP Chat V3.0.0 Beta1. It allows an attacker to include arbitrary remote files via the 'basepath' parameter in multiple scripts.
Description
Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Mazen's PHP Chat V3.0.0 Beta1. It allows an attacker to include arbitrary remote files via the 'basepath' parameter in multiple scripts.