vendor:
Flashchat
by:
NeXtMaN
7,5
CVSS
HIGH
Remote File Inclusion (RFI)
98
CWE
Product Name: Flashchat
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
RFI Vulnerabilities in Flashchat
The vulnerable files are present in case of integration with another script, AEDating. The vulnerable files are aedating4CMS.php, aedatingCMS.php and aedatingCMS2.php. An attacker can exploit this vulnerability by sending a malicious URL to the vulnerable server. The malicious URL contains a reference to a file on a remote server which will be included in the application and executed.
Mitigation:
Delete the vulnerable files or edit the 3 files to use the path of AEDating. Alternatively, upgrade to 4.6.2.