XOOPS < 126.96.36.199 include/common.php nocommon Parameter Local File Inclusion
Medium Nessus Network Monitor Plugin ID 3629
SynopsisThe remote web server contains a PHP application that is vulnerable to local file include attacks.
DescriptionThe version of XOOPS installed on the remote host allows an unauthenticated attacker to skip processing of the application's 'include/common.php' script and thereby to gain control of the variables '$xoopsConfig[language]' and '$xoopsConfig[theme_set]', which are used by various scripts to include PHP code from other files. Successful exploitation of these issues requires that PHP's 'register_globals' setting be enabled and can be used to view arbitrary files or to execute arbitrary PHP code on the remote host, subject to the privileges of the web server user ID.
SolutionUpgrade to version 188.8.131.52 or higher.