7.5
CVSSv2

CVE-2005-2113

Published: 05/07/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and previous versions allows remote malicious users to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops xoops 2.0

xoops xoops 2.0.1

xoops xoops 2.0.5.1

xoops xoops 2.0.5.2

xoops xoops 2.0.4

xoops xoops 2.0.5

xoops xoops 2.0.10

xoops xoops 2.0.11

xoops xoops 2.0.6

xoops xoops 2.0.7

xoops xoops 2.0.2

xoops xoops 2.0.3

xoops xoops 2.0.9

xoops xoops 2.0.9.2

xoops xoops 2.0.9.3

Exploits

#!/usr/bin/perl ## Xoops <= 2011 xmlrpcphp sql injection exploit by RST/GHC ## based on wwwgulftechorg/?node=research&article_id=00086-06292005 ## coded by 1dtw0lf ## RST/GHC ## rstvoidru ## ghcru ## example: ## r57xoopspl -u wwwxoops2ru/xmlrpcphp -n Alexxus ## ------------------------------------- ...
XOOPS Multiple Vulnerabilities Vendor: XOOPS Product: XOOPS Version: <= 2011 Website: wwwxoopsorg/ BID: 14094 14096 CVE: CVE-2005-2112 CVE-2005-2113 OSVDB: 17633 17634 17635 SECUNIA: 15843 PACKETSTORM: 38372 Description: XOOPS is a very popular dynamic web content management system written in Object Oriented PHP One of the fe ...