CVE-2003-1550
XOOPS < 2.0 - Exposure of Sensitive Information via Invalid xoopsOption Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1550. PoCs published by gregory Le Bras.
AI-analyzed exploit summary The provided text describes an information disclosure vulnerability in XOOPS 2.0, where server error messages may expose path information and other sensitive data. The example URL demonstrates how an attacker can trigger this behavior by manipulating the 'xoopsOption' parameter.
Description
XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.
Exploits (1)
The provided text describes an information disclosure vulnerability in XOOPS 2.0, where server error messages may expose path information and other sensitive data. The example URL demonstrates how an attacker can trigger this behavior by manipulating the 'xoopsOption' parameter.