CVE-2005-3680: Medium severity Xoops Xoops vulnerability
Directory traversal vulnerability in editorregistry.php in XOOPS 2.2.3 allows remote attackers to read or include arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3680?
CVE-2005-3680 has been classified as a high severity vulnerability due to its ability to allow unauthorized access to arbitrary local files.
How do I fix CVE-2005-3680?
To fix CVE-2005-3680, upgrade your XOOPS installation to a version beyond 2.2.3 where this vulnerability is patched.
What type of attack can exploit CVE-2005-3680?
CVE-2005-3680 can be exploited by remote attackers using directory traversal techniques to read or include sensitive files from the server.
Which versions of XOOPS are affected by CVE-2005-3680?
CVE-2005-3680 specifically affects XOOPS version 2.2.3.
What is the primary impact of CVE-2005-3680 on web applications?
The primary impact of CVE-2005-3680 is the unauthorized disclosure of sensitive information from local files on the server.