CVE-2007-3236
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.
- Affected products
- Xoops
- Xoops Horoscope Module
- = 1.0
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 77.0% (100th percentile)
- NVD status
- Modified
- Published
- 2007-06-15
CVE-2007-3236 at NVD
2 known exploits for CVE-2007-3236
Proof-of-concept code and exploit modules indexed by Sploitus