Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v9 - Exploits Update (Wed Jul 22 2009)

XOOPS mydirname Remote Code Execution Exploit

Exploits/Remote  [Linux]




• Wed Jul 22 2009
This module exploits a lack of data sanitization when passed to the "mydirname" parameter in specific modules of XOOP web application. This can be exploited to inject and execute arbitrary PHP code to deploy an agent. Successful exploitation requires that "register_globals" is enabled.

Exploits Vulnerabiltiy: NOCVE-9999-38580



< Back to Product Updates