The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.
Link | Tags |
---|---|
http://secunia.com/advisories/14520 | third party advisory patch vendor advisory |
http://www.xoops.org/modules/news/article.php?storyid=2114 | patch |
http://www.securityfocus.com/archive/1/392626 | mailing list patch |
http://www.securityfocus.com/bid/12754 | vdb entry patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19634 | vdb entry |