PT-2007-4349 · Xoops · Xoops

Gold_M

·

Published

2007-06-06

·

Updated

2017-10-11

·

CVE-2007-3057

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: XOOPS icontent module version 4.5
Description: A remote file inclusion issue exists, allowing remote attackers to execute arbitrary PHP code via a URL in the spaw root parameter in the include/wysiwyg/spaw control.class.php file.
Recommendations: For XOOPS icontent module version 4.5, consider restricting access to the spaw control.class.php file until a patch is available. Avoid using the spaw root parameter in the affected module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3057

Affected Products

Xoops