Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-5188
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5188

Description:
Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA27006

OSVDB
  41386

CONFIRM
  http://www.xoops.org/modules/news/article.php?storyid=3963
  http://sourceforge.net/project/shownotes.php?group_id=41586&release_id=543338

BID
  25878


Return to the previous page.