Back

CVE-2005-3680

Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers to read or include arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter.

Published: Nov 18, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
xoops xoops 2.2.3

GitHub Security Advisory GHSA-m685-cgj3-vw9m

Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.72%

Top 24% most likely to be exploited

Threat Score 26.1 / 100

Data Sources

NVD EPSS GitHub