CVE

Id
25333  
CVE No.
CVE-2007-1976  
Status
Candidate  
Description
** DISPUTED ** PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application"s checkSuperglobals function defends against the attack.  
Phase
Assigned (20070411)  
Votes
None (candidate not yet proposed)  
Comments