CVE-2007-3289: High severity Xoops Wiwimod Module vulnerability
Published Jun 20, 2007
·Updated
PHP remote file inclusion vulnerability in spaw/spawcontrol.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spawroot parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
Affected Software
1 affected component
Xoops Wiwimod Module=0.4
Event History
Jun 20, 2007
CVE Published
09:30 PM
Jun 21, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3289?
CVE-2007-3289 is considered a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2007-3289?
To fix CVE-2007-3289, update to a version of the WiwiMod module for XOOPS that addresses this vulnerability.
3
What type of vulnerability is CVE-2007-3289?
CVE-2007-3289 is a remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
4
Which software is affected by CVE-2007-3289?
CVE-2007-3289 specifically affects the WiwiMod version 0.4 module for XOOPS.
5
Can CVE-2007-3289 be exploited easily?
Yes, CVE-2007-3289 can be exploited easily if the spaw_root parameter is not properly validated.