Flat Chat Startsession.PHP Remote PHP Code Execution Vulnerability

Attackers can exploit this issue via a web client.

A sample proof-of-concept URI has been provided:

http://example.com/flatchat/users.php?cmd=ls -la


 

Privacy Statement
Copyright 2010, SecurityFocus