Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

XOOPS < include/common.php nocommon Parameter Local File Inclusion



The remote web server contains a PHP application that is vulnerable to local file include attacks.


The version of XOOPS installed on the remote host allows an unauthenticated attacker to skip processing of the application's 'include/common.php' script and thereby to gain control of the variables '$xoopsConfig[language]' and '$xoopsConfig[theme_set]', which are used by various scripts to include PHP code from other files. Successful exploitation of these issues requires that PHP's 'register_globals' setting be enabled and can be used to view arbitrary files or to execute arbitrary PHP code on the remote host, subject to the privileges of the web server user ID.


Upgrade to version or higher.