CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
81.9%
PHP remote file inclusion vulnerability in adminips.php in Develooping Flash Chat allows remote attackers to execute arbitrary PHP code via a URL in the banned_file parameter. NOTE: CVE disputes this vulnerability because banned_file is set to a constant value
Vendor | Product | Version | CPE |
---|---|---|---|
develooping | flash_chat | 4.5.7 | cpe:2.3:a:develooping:flash_chat:4.5.7:*:*:*:*:*:*:* |
develooping | flash_chat | 4.6 | cpe:2.3:a:develooping:flash_chat:4.6:*:*:*:*:*:*:* |
develooping | flash_chat | 4.6.1 | cpe:2.3:a:develooping:flash_chat:4.6.1:*:*:*:*:*:*:* |