The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xoops | Xoops | 1.0_rc1 (including) | 1.0_rc1 (including) |
Xoops | Xoops | 1.0_rc3 (including) | 1.0_rc3 (including) |
Xoops | Xoops | 1.0_rc3.0.5 (including) | 1.0_rc3.0.5 (including) |
Xoops | Xoops | 1.3.5 (including) | 1.3.5 (including) |
Xoops | Xoops | 1.3.6 (including) | 1.3.6 (including) |
Xoops | Xoops | 1.3.7 (including) | 1.3.7 (including) |
Xoops | Xoops | 1.3.8 (including) | 1.3.8 (including) |
Xoops | Xoops | 1.3.9 (including) | 1.3.9 (including) |
Xoops | Xoops | 1.3.10 (including) | 1.3.10 (including) |
Xoops | Xoops | 2.0 (including) | 2.0 (including) |
Xoops | Xoops | 2.0.1 (including) | 2.0.1 (including) |
Xoops | Xoops | 2.0.2 (including) | 2.0.2 (including) |
Xoops | Xoops | 2.0.3 (including) | 2.0.3 (including) |
Xoops | Xoops | 2.0.5 (including) | 2.0.5 (including) |
Xoops | Xoops | 2.0.5.1 (including) | 2.0.5.1 (including) |
Xoops | Xoops | 2.0.5.2 (including) | 2.0.5.2 (including) |
Xoops | Xoops | 2.0.9.2 (including) | 2.0.9.2 (including) |