CVE-2008-6884: Path Traversal
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when registerglobals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter to (1) blocks.php and (2) main.php in xoopslib/modules/protector/.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6884?
CVE-2008-6884 is considered a high severity vulnerability due to its potential for arbitrary file inclusion.
How do I fix CVE-2008-6884?
To fix CVE-2008-6884, disable register_globals and upgrade to a patched version of XOOPS.
Who is affected by CVE-2008-6884?
CVE-2008-6884 affects users of XOOPS version 2.3.1 with register_globals enabled.
What kind of attacks can be executed using CVE-2008-6884?
Using CVE-2008-6884, attackers can perform directory traversal attacks to include and execute arbitrary local files.
Is CVE-2008-6884 still a risk for current versions of XOOPS?
CVE-2008-6884 primarily impacts version 2.3.1, and newer versions of XOOPS have addressed this vulnerability.