Quote:
Originally Posted by <MG>CP
Seems too risky for me 
|
Well it makes no difference to me, Flashchat isn't mine, but you really should make the effort to read what you link to.
That exploit is ancient, the date is in the title, as is the fact it was for versions < 4.5.7 (the current version is 4.7.7)
Quote:
2006-09-04 FlashChat <= 4.5.7 (aedating4CMS.php) Remote File Include Vulnerability
|
(and although it's not mentioned in that post, it was only exploitable if you a) left all the CMS files on the server and b) you had "register globals" enabled in php. The latter of those is a security risk in php itself).