mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['nocommon'] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to misc.php or (2) xoopsConfig[theme_set] to index.php, as demonstrated by injecting PHP sequences into a log file.
2006-05-22T22:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.1 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | xoops | xoops | ≤ 2.0.13.2 | Yes |
Application | xoops | xoops | 2.0 | Yes |
Application | xoops | xoops | 2.0.1 | Yes |
Application | xoops | xoops | 2.0.2 | Yes |
Application | xoops | xoops | 2.0.3 | Yes |
Application | xoops | xoops | 2.0.4 | Yes |
Application | xoops | xoops | 2.0.5 | Yes |
Application | xoops | xoops | 2.0.5.1 | Yes |
Application | xoops | xoops | 2.0.5.2 | Yes |
Application | xoops | xoops | 2.0.6 | Yes |
Application | xoops | xoops | 2.0.7 | Yes |
Application | xoops | xoops | 2.0.9 | Yes |
Application | xoops | xoops | 2.0.9.2 | Yes |
Application | xoops | xoops | 2.0.9.3 | Yes |
Application | xoops | xoops | 2.0.10 | Yes |
Application | xoops | xoops | 2.0.11 | Yes |
Application | xoops | xoops | 2.0.12_jp | Yes |
Application | xoops | xoops | 2.0.13.1 | Yes |