PT-2007-6281 · Xoops · Xoops
Phppp
·
Published
2007-10-03
·
Updated
2011-03-08
·
CVE-2007-5188
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xoops versions 2.0.17.1-RC1 and earlier
Description
The issue is related to an unspecified vulnerability in the XOOPS uploader class, allowing remote attackers to upload arbitrary files. This is possibly due to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, which may include an incomplete blacklist that omits the .php4 extension.
Recommendations
For Xoops versions 2.0.17.1-RC1 and earlier, consider restricting access to the uploader class until a fix is available. As a temporary workaround, review and update the upload configuration settings in class/uploader.php and class/mimetypes.inc.php to ensure that all potentially executable file extensions, including .php4, are properly blacklisted.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xoops