XOOPS module XFsection versions below 1.07 suffer from a remote file inclusion vulnerability in modify.php.