CORE IMPACT v9 - Exploits Update (Wed Jul 22 2009)
XOOPS mydirname Remote Code Execution Exploit
Exploits/Remote [Linux]
Wed Jul 22 2009
This module exploits a lack of data sanitization when passed to the "mydirname" parameter in specific modules of XOOP web application. This can be exploited to inject and execute arbitrary PHP code to deploy an agent. Successful exploitation requires that "register_globals" is enabled.
Exploits Vulnerabiltiy: NOCVE-9999-38580











