Vulnerabilities > CVE-2005-2113 - Unspecified vulnerability in Xoops
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 15 |
Exploit-Db
description XOOPS <= 2.0.11 xmlrpc.php SQL Injection Exploit. CVE-2005-2113. Webapps exploit for php platform id EDB-ID:1082 last seen 2016-01-31 modified 2005-07-04 published 2005-07-04 reporter RusH source https://www.exploit-db.com/download/1082/ title XOOPS <= 2.0.11 xmlrpc.php SQL Injection Exploit description XOOPS < 2.0.11 - Multiple Vulnerabilities. CVE-2005-2112,CVE-2005-2113. Webapps exploit for PHP platform id EDB-ID:43827 last seen 2018-01-24 modified 2015-06-29 published 2015-06-29 reporter Exploit-DB source https://www.exploit-db.com/download/43827/ title XOOPS < 2.0.11 - Multiple Vulnerabilities
Nessus
NASL family | CGI abuses |
NASL id | XOOPS_2012.NASL |
description | The installed version of XOOPS on the remote host is affected by several vulnerabilities : - A SQL Injection Vulnerability The bundled XMLRPC server fails to sanitize user- supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18614 |
published | 2005-07-05 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18614 |
title | XOOPS < 2.0.12 Multiple Vulnerabilities |
References
- http://marc.info/?l=bugtraq&m=112006318512991&w=2
- http://marc.info/?l=bugtraq&m=112006318512991&w=2
- http://secunia.com/advisories/15843
- http://secunia.com/advisories/15843
- http://www.gulftech.org/?node=research&article_id=00086-06292005
- http://www.gulftech.org/?node=research&article_id=00086-06292005
- http://www.xoops.org/modules/news/article.php?storyid=2383
- http://www.xoops.org/modules/news/article.php?storyid=2383