CVE-2008-3296
XOOPS 2.0.18.1 - Path Traversal and Arbitrary File Execution via fct Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3296. PoCs published by Ciph3r.
AI-analyzed exploit summary The provided text describes a local file inclusion (LFI) and cross-site scripting (XSS) vulnerability in XOOPS 2.0.18.1. It includes a sample exploit URL for LFI but lacks executable code.
Description
Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The provided text describes a local file inclusion (LFI) and cross-site scripting (XSS) vulnerability in XOOPS 2.0.18.1. It includes a sample exploit URL for LFI but lacks executable code.