XOOPS Arbitrary File Deletion and HTTP Header Injection Vulnerabilities
BID:37860
Info
XOOPS Arbitrary File Deletion and HTTP Header Injection Vulnerabilities
| Bugtraq ID: | 37860 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | No |
| Published: | Jan 19 2010 12:00AM |
| Updated: | Jan 19 2010 12:00AM |
| Credit: | CodeScan Labs |
| Vulnerable: |
Xoops Xoops 2.4.3 Xoops Xoops 2.4.2 Xoops Xoops 2.4.1 Xoops Xoops 2.4.1 Xoops Xoops 2.4 Xoops Xoops 2.3.3 Xoops Xoops 2.3.2 b Xoops Xoops 2.3.2 Xoops Xoops 2.2.5 Xoops Xoops 2.2.3 RC1 Xoops Xoops 2.2.3 Xoops Xoops 2.2.1 Xoops Xoops 2.0.18 .1 Xoops Xoops 2.0.18 Xoops Xoops 2.0.17 1 Xoops Xoops 2.0.15 Xoops Xoops 2.0.14 Xoops Xoops 2.0.13 .2 Xoops Xoops 2.0.13 .1 Xoops Xoops 2.0.12 a Xoops Xoops 2.0.12 Xoops Xoops 2.0.11 Xoops Xoops 2.0.10 Xoops Xoops 2.0.9 .3 Xoops Xoops 2.0.9 .2 Xoops Xoops 2.0.5 .2 Xoops Xoops 2.0.5 .1 Xoops Xoops 2.0.5 Xoops Xoops 2.0.3 Xoops Xoops 2.0.2 Xoops Xoops 2.0.1 Xoops Xoops 2.0 Xoops Xoops 2.3 Xoops Xoops 2.0.16 core |
| Not Vulnerable: | |
Exploit / POC
XOOPS Arbitrary File Deletion and HTTP Header Injection Vulnerabilities
Attackers can exploit these issues through a browser. For some attacks, a vulnerable user may have to follow a malicious link.
Attackers can exploit these issues through a browser. For some attacks, a vulnerable user may have to follow a malicious link.
References
XOOPS Arbitrary File Deletion and HTTP Header Injection Vulnerabilities
References:
References:
- Multiple vulnerablities in Xoops 2.4.3 (CodeScan Labs)
- XOOPS Homepage (XOOPS)
- Multiple Vulnerabilities in XOOPS 2.4.3 and earlier (CodeScan Labs Advisories
)