First published: Sun Apr 27 2008(Updated: )
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | ||
123 Flash Chat Module | =6.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1989 is considered a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2008-1989, disable register_globals and update to the latest version of the affected software.
CVE-2008-1989 affects the e107 CMS and the 123 Flash Chat module version 6.8.0.
Yes, CVE-2008-1989 can be exploited remotely by an attacker via a crafted URL.
The attack vector for CVE-2008-1989 involves the e107path parameter within the 123flashchat.php file.