CVE-2007-3220: Medium severity Xoops Cjay Content Module vulnerability
Published Jun 14, 2007
·Updated
PHP remote file inclusion vulnerability in admin/editor2/spawcontrol.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spawroot parameter. NOTE: this may be a duplicate of CVE-2006-4656.
Affected Software
1 affected component
Xoops Cjay Content Module=3
Event History
Jun 14, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3220?
The severity of CVE-2007-3220 is considered high due to its potential to allow remote code execution.
2
How do I fix CVE-2007-3220?
To fix CVE-2007-3220, update to the latest version of the Cjay Content module for XOOPS that addresses this vulnerability.
3
What systems are affected by CVE-2007-3220?
CVE-2007-3220 affects version 3 of the Cjay Content module for XOOPS.
4
What type of vulnerability is CVE-2007-3220?
CVE-2007-3220 is classified as a PHP remote file inclusion vulnerability.
5
Can CVE-2007-3220 impact server security?
Yes, CVE-2007-3220 can significantly impact server security by allowing attackers to execute arbitrary PHP code.