|
CVE Reference: CVE-2007-1896
|
|
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.
|
|
Original Page at CVE MITRE:
CVE-2007-1896
|
|
Description:
Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a my_ms[root] cookie.
|
|
CVE Status:
Candidate
|
|
References:
SAID Secunia Advisory: SA24760 Secunia Advisory: SA24766
OSVDB 34146
MILW0RM http://www.milw0rm.com/exploits/3657
|
|
|
Return to the previous page.
|