PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when registerglobals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.
DISPUTED Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter to (1) 123flashchat.php and (2) phpbbloginchat.php. NOTE: CVE disputes this issue because $phpbbrootpath is explicitly set to "./" in both programs.