|
|
|
|
|
|
|
| |
XOOPS XFSection Module modify.php dir_module Parameter Remote File Inclusion |
|
| This script is Copyright (C) 2007-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 25493 (xoops_xfsection_dir_module_file_include.nasl) |
| Bugtraq ID | 24465
|
| CVE ID | CVE-2007-3222
|
|
| Description: |
Synopsis :
The remote web server contains a PHP script that is affected by a
remote file include vulnerability.
Description :
The remote host is running XFSection, a third-party module for XOOPS.
The version of this module installed on the remote host fails to
sanitize input to the 'dir_module' parameter of the 'modify.php'
script before using it to include PHP code. Regardless of PHP's
'register_globals' setting, an unauthenticated attacker can exploit
this issue to view arbitrary files on the remote host or possibly to
execute arbitrary PHP code, perhaps from third-party hosts.
See also :
http://www.milw0rm.com/exploits/4068
Solution :
Unknown at this time.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|