First published: Thu Apr 12 2007(Updated: )
** DISPUTED ** PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application's checkSuperglobals function defends against the attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Virii Info Module | <=1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1976 is classified as a remote file inclusion vulnerability that may allow arbitrary code execution.
To fix CVE-2007-1976, upgrade the Xoops Virii Info module to a version later than 1.10 or apply any available security patches.
CVE-2007-1976 affects the Virii Info module for Xoops version 1.10 and earlier.
Yes, CVE-2007-1976 can be exploited remotely by attackers to execute arbitrary PHP code.
CVE-2007-1976 may still pose a threat if users have not updated to secure versions of the Xoops Virii Info module.