CVE-2008-6884 | XOOPS 2.3.1 blocks.php xoopsConfig[language] path traversal (EDB-7380 / Nessus ID 35278)
A vulnerability classified as critical has been found in XOOPS 2.3.1. Affected is an unknown function in the library xoops_lib/modules/protector/ of the file blocks.php. The manipulation of the argument xoopsConfig[language] leads to path traversal.
This vulnerability is traded as CVE-2008-6884. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.