XOOPS 'lang' Parameter Local File Include Vulnerability
BID:27622
Info
XOOPS 'lang' Parameter Local File Include Vulnerability
| Bugtraq ID: | 27622 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0612 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Alexandr Polyakov and Stas Svistunovich discovered this vulnerability. |
| Vulnerable: |
Xoops Xoops 2.0.18 |
| Not Vulnerable: | |
Discussion
XOOPS 'lang' Parameter Local File Include Vulnerability
XOOPS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to access potentially sensitive information and execute arbitrary local scripts in the context of the affected application.
This issue affects XOOPS 2.0.18; other versions may also be vulnerable.
XOOPS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to access potentially sensitive information and execute arbitrary local scripts in the context of the affected application.
This issue affects XOOPS 2.0.18; other versions may also be vulnerable.
Exploit / POC
XOOPS 'lang' Parameter Local File Include Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
XOOPS 'lang' Parameter Local File Include Vulnerability
Solution:
A fix is available in the SVN repository. Please see the references for more information.
Solution:
A fix is available in the SVN repository. Please see the references for more information.
References
XOOPS 'lang' Parameter Local File Include Vulnerability
References:
References: