Vulnerabilities > CVE-2007-3222 - Remote File Include vulnerability in Xoops Xfsection Module 1.07

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
xoops
nessus
exploit available

Summary

PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.

Vulnerable Configurations

Part Description Count
Application
Xoops
1

Exploit-Db

descriptionXOOPS Module XFsection (modify.php) Remote File Inclusion Vulnerability. CVE-2007-3222. Webapps exploit for php platform
fileexploits/php/webapps/4068.txt
idEDB-ID:4068
last seen2016-01-31
modified2007-06-13
platformphp
port
published2007-06-13
reporterSp[L]o1T
sourcehttps://www.exploit-db.com/download/4068/
titleXOOPS Module XFsection modify.php Remote File Inclusion Vulnerability
typewebapps

Nessus

NASL familyCGI abuses
NASL idXOOPS_XFSECTION_DIR_MODULE_FILE_INCLUDE.NASL
descriptionThe remote host is running XFSection, a third-party module for XOOPS. The version of this module installed on the remote host fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id25493
published2007-06-14
reporterThis script is Copyright (C) 2007-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/25493
titleXOOPS XFSection Module modify.php dir_module Parameter Remote File Inclusion