CVE-2008-1989
123 Flash Chat 6.8.0 module for e107 - Remote Code Execution via e107path Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1989. PoCs published by by_casper41.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in the E107 Chat Module 123FlashChat. The vulnerability allows an attacker to include a remote shell by manipulating the 'e107path' parameter in the '123flashchat.php' file.
Description
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in the E107 Chat Module 123FlashChat. The vulnerability allows an attacker to include a remote shell by manipulating the 'e107path' parameter in the '123flashchat.php' file.