Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) sequences in the help_file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
X7_chat | X7_group | 1.3.2b (including) | 1.3.2b (including) |
X7_chat | X7_group | 1.3.3b (including) | 1.3.3b (including) |
X7_chat | X7_group | 1.3.4b (including) | 1.3.4b (including) |
X7_chat | X7_group | 1.3.5b (including) | 1.3.5b (including) |
X7_chat | X7_group | 1.3.6 (including) | 1.3.6 (including) |
X7_chat | X7_group | 2.0 (including) | 2.0 (including) |