CVE-2007-6675: Medium severity xoops xm memberstats vulnerability
Published Jan 8, 2008
·Updated
The bsystemcommentsshow function in htdocs/modules/system/blocks/systemblocks.php in XOOPS before 2.0.18 does not check permissions, which allows remote attackers to read the comments in restricted modules.
Affected Software
1 affected component
Xoops Xoops<=2.0.17_1
Event History
Jan 8, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6675?
CVE-2007-6675 has a medium severity due to the potential for unauthorized access to restricted comments.
2
How do I fix CVE-2007-6675?
To fix CVE-2007-6675, upgrade to XOOPS version 2.0.18 or later, which includes permission checks for comments.
3
What software is affected by CVE-2007-6675?
CVE-2007-6675 affects XOOPS versions before 2.0.18, specifically up to 2.0.17_1.
4
What type of vulnerability is CVE-2007-6675?
CVE-2007-6675 is an access control vulnerability that allows unauthorized users to view restricted comments.
5
Who can exploit CVE-2007-6675?
Remote attackers can exploit CVE-2007-6675 to read comments in restricted modules without proper permissions.