Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Mpm_chat |
Mpm_chat |
2.5 (including) |
2.5 (including) |
References