Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-2516

mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['nocommon'] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to misc.php or (2) xoopsConfig[theme_set] to index.php, as demonstrated by injecting PHP sequences into a log file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.052
EPSS Ranking 89.4%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2006-2516
  • Xoops » Xoops » Version: Any
    cpe:2.3:a:xoops:xoops:*
  • Xoops » Xoops » Version: 2.0
    cpe:2.3:a:xoops:xoops:2.0
  • Xoops » Xoops » Version: 2.0.1
    cpe:2.3:a:xoops:xoops:2.0.1
  • Xoops » Xoops » Version: 2.0.10
    cpe:2.3:a:xoops:xoops:2.0.10
  • Xoops » Xoops » Version: 2.0.11
    cpe:2.3:a:xoops:xoops:2.0.11
  • Xoops » Xoops » Version: 2.0.12_jp
    cpe:2.3:a:xoops:xoops:2.0.12_jp
  • Xoops » Xoops » Version: 2.0.13.1
    cpe:2.3:a:xoops:xoops:2.0.13.1
  • Xoops » Xoops » Version: 2.0.2
    cpe:2.3:a:xoops:xoops:2.0.2
  • Xoops » Xoops » Version: 2.0.3
    cpe:2.3:a:xoops:xoops:2.0.3
  • Xoops » Xoops » Version: 2.0.4
    cpe:2.3:a:xoops:xoops:2.0.4
  • Xoops » Xoops » Version: 2.0.5
    cpe:2.3:a:xoops:xoops:2.0.5
  • Xoops » Xoops » Version: 2.0.5.1
    cpe:2.3:a:xoops:xoops:2.0.5.1
  • Xoops » Xoops » Version: 2.0.5.2
    cpe:2.3:a:xoops:xoops:2.0.5.2
  • Xoops » Xoops » Version: 2.0.6
    cpe:2.3:a:xoops:xoops:2.0.6
  • Xoops » Xoops » Version: 2.0.7
    cpe:2.3:a:xoops:xoops:2.0.7
  • Xoops » Xoops » Version: 2.0.9
    cpe:2.3:a:xoops:xoops:2.0.9
  • Xoops » Xoops » Version: 2.0.9.2
    cpe:2.3:a:xoops:xoops:2.0.9.2
  • Xoops » Xoops » Version: 2.0.9.3
    cpe:2.3:a:xoops:xoops:2.0.9.3


Contact Us

Shodan ® - All rights reserved