This application requires Javascript for optimal performance.

FlashChat.Multiple.Remote.File.Inclusion

Alias(es)

FlashChat.Multiple.Remote.File.Include

Release Date

Jan 29, 2007

Severity

high

Impact

Gain Access

Description

FlashChat has a multiple remote file-include vulnerability. A remote attacker could execute arbitrary code on the Web server by sending a specially crafted URL request to the aedating4CMS.php, aedatingCMS2.php, or aedatingCMS.php script, using the dir[inc] parameter to specify a malicious file from a remote system.

Affected Products

FlashChat versions prior to 4.6.2

Recommended Actions

Update the software to last version
http://www.tufat.com/download.php

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4583

Reference/s

http://www.securityfocus.com/bid/19826 (BugTraq)

Reference: VID-13941