30022Third-party advisory
http://secunia.com/advisories/30022 CVE-2008-2074
Harris WapChat 1 - Multiple Remote File Inclusions
Record summary
CVE-2008-2074 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHarris WapChat 1 - Multiple Remote File InclusionsExploitDB exploitby k1n9k0ngNot analyzed1 file
References
528995vdb entry
http://www.securityfocus.com/bid/28995 harriswapchat-sysfiledir-file-include(42112)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42112 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2074 5525exploit
https://www.exploit-db.com/exploits/5525