Back
CVE-2005-3680
Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers to read or include arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter.
Published: Nov 18, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| xoops | xoops | 2.2.3 |
GitHub Security Advisory GHSA-m685-cgj3-vw9m
Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers...
References (8)
- http://marc.info/?l=bugtraq&m=113199244824660&w=2
- http://secunia.com/advisories/17573/ Vendor Advisory
- http://www.securityfocus.com/bid/15406/ Exploit
- http://www.vupen.com/english/advisories/2005/2428
- http://marc.info/?l=bugtraq&m=113199244824660&w=2
- http://secunia.com/advisories/17573/ Vendor Advisory
- http://www.securityfocus.com/bid/15406/ Exploit
- http://www.vupen.com/english/advisories/2005/2428
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
1.72%
Top 24% most likely to be exploited
Threat Score
26.1 / 100
Data Sources
NVD
EPSS
GitHub