CVE-2007-3237: Medium severity Xoops Tinycontent Module vulnerability
PHP remote file inclusion vulnerability in admin/spaw/spawcontrol.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spawroot parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3237?
CVE-2007-3237 is classified as a medium severity vulnerability due to the potential for remote file inclusion leading to arbitrary PHP code execution.
How do I fix CVE-2007-3237?
To fix CVE-2007-3237, upgrade the TinyContent module for XOOPS to a version that does not allow remote file inclusion.
What systems are affected by CVE-2007-3237?
CVE-2007-3237 affects the TinyContent module version 1.5 for XOOPS.
What type of vulnerability is CVE-2007-3237?
CVE-2007-3237 is a remote file inclusion vulnerability allowing remote attackers to execute arbitrary PHP code.
Can CVE-2007-3237 be exploited remotely?
Yes, CVE-2007-3237 can be exploited remotely by an attacker using a crafted URL containing malicious code.