CVE-2007-3057: Medium severity Xoops Icontent Module vulnerability
PHP remote file inclusion vulnerability in include/wysiwyg/spawcontrol.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spawroot parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3057?
CVE-2007-3057 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2007-3057?
To fix CVE-2007-3057, it is recommended to upgrade to a version of the XOOPS Icontent module that is not affected by this vulnerability.
What type of vulnerability is CVE-2007-3057?
CVE-2007-3057 is a PHP remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
Which software is affected by CVE-2007-3057?
CVE-2007-3057 affects the XOOPS Icontent Module version 4.5.
Can CVE-2007-3057 lead to data compromise?
Yes, CVE-2007-3057 can lead to data compromise as it allows remote attackers to execute arbitrary PHP code.