CVE-2007-1895 Information

Description

PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier when used with PHP 5 allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie a different vector than CVE-2007-0491 and CVE-2006-4630.

Reference

http://osvdb.org/34145 http://secunia.com/advisories/24760 http://www.vupen.com/english/advisories/2007/1261 https://www.exploit-db.com/exploits/3657

Share on: