Multiple PHP remote file inclusion vulnerabilities in Mazens PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mazens_php_chat | Mazens_php_chat | 3.0.0 (including) | 3.0.0 (including) |