CVE-2008-4718
X7 Chat < 2.0.1 - Path Traversal and Arbitrary File Execution via Help File Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4718. PoCs published by JIKO, NoGe.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in X7 Chat Version 2.0.1. The vulnerability allows an attacker to include arbitrary local files via the 'help_file' parameter in the 'mini.php' script.
Description
Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the help_file parameter, a different vector than CVE-2006-2156.
Exploits (2)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in X7 Chat Version 2.0.1. The vulnerability allows an attacker to include arbitrary local files via the 'help_file' parameter in the 'mini.php' script.
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in X7 Chat <= 2.0.1A1 via the 'help_file' parameter in help/mini.php. The vulnerability arises from unsanitized user input being directly included in a file path, allowing arbitrary file inclusion via null byte injection.