vendor:
XOOPS
by:
Digital Security Research Group [DSecRG]
4.3
CVSS
MEDIUM
Multiple Local File Include
98
CWE
Product Name: XOOPS
Affected Version From: 2.3.2001
Affected Version To: 2.3.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:xoops:xoops
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
DSECRG-08-040
XOOPS has Multiple Local File Include vulnerabilities. Local File Include vulnerability found in scripts: xoops_lib/modules/protector/blocks.php and xoops_lib/modules/protector/main.php. Successful exploitation requires that "register_globals" is enabled. For successful exploitation first condition in if..else statement must be not true.
Mitigation:
Vendor fixed tis vulnerability in version 2.3.2.