5
CVSSv2

CVE-2007-6675

Published: 08/01/2008 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS prior to 2.0.18 does not check permissions, which allows remote malicious users to read the comments in restricted modules.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops xoops