CVE-2007-3236: High severity Xoops Horoscope Module vulnerability
Published Jun 15, 2007
·Updated
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[rootpath] parameter.
Affected Software
1 affected component
Xoops Horoscope Module=1.0
Event History
Jun 15, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3236?
CVE-2007-3236 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2007-3236?
To fix CVE-2007-3236, it is recommended to upgrade the Horoscope module for XOOPS to a version that does not contain this vulnerability.
3
Who is affected by CVE-2007-3236?
CVE-2007-3236 affects users of the Horoscope 1.0 module for XOOPS specifically.
4
What type of vulnerability is CVE-2007-3236?
CVE-2007-3236 is a remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
5
What component of XOOPS is impacted by CVE-2007-3236?
CVE-2007-3236 impacts the footer.php file within the Horoscope 1.0 module for XOOPS.