activeCollab Chat Module Arbitrary PHP Code Execution Vulnerability

activeCollab Chat Module is prone to a remote PHP code-execution vulnerability.

An attacker can exploit this issue to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Versions prior to activeCollab Chat Module 1.5.2 are vulnerable.


Privacy Statement
Copyright 2010, SecurityFocus