CVE-2008-6884

Xoops - Path Traversal

Title source: rule

Description

Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter to (1) blocks.php and (2) main.php in xoops_lib/modules/protector/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DSecRG · textwebappsphp
https://www.exploit-db.com/exploits/7380

Scores

EPSS 0.0566
EPSS Percentile 90.2%

Classification

CWE
CWE-22
Status draft

Affected Products (1)

xoops/xoops

Timeline

Published Jul 31, 2009
Tracked Since Feb 18, 2026