CVE-2007-5620
ZZ:FlashChat < 3.1 - Path Traversal via Help File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5620. PoCs published by d3hydr8.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in ZZ:FlashChat via the 'file' parameter in /chat/admin/inc/help.php. The vulnerability allows an attacker to include arbitrary local files, potentially leading to information disclosure or remote code execution if combined with other techniques.
Description
Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in ZZ:FlashChat via the 'file' parameter in /chat/admin/inc/help.php. The vulnerability allows an attacker to include arbitrary local files, potentially leading to information disclosure or remote code execution if combined with other techniques.