First published: Wed Feb 06 2008(Updated: )
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-xoops | =2.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0612 is classified as a medium severity vulnerability due to its potential for arbitrary file inclusion.
To mitigate CVE-2008-0612, upgrade XOOPS to version 2.0.18.1 or later, which addresses this vulnerability.
CVE-2008-0612 affects XOOPS version 2.0.18 specifically through its htdocs/install/index.php file.
CVE-2008-0612 can be exploited by remote attackers to include and execute arbitrary local files on vulnerable systems.
While CVE-2008-0612 is an older vulnerability, it can still pose a threat if affected versions of XOOPS remain unpatched.