The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xoops | Xoops | * | 2.4.0 (including) |
Xoops | Xoops | 1.0 (including) | 1.0 (including) |
Xoops | Xoops | 1.0_rc1 (including) | 1.0_rc1 (including) |
Xoops | Xoops | 1.0_rc3 (including) | 1.0_rc3 (including) |
Xoops | Xoops | 1.0_rc3.0.5 (including) | 1.0_rc3.0.5 (including) |
Xoops | Xoops | 1.3.5 (including) | 1.3.5 (including) |
Xoops | Xoops | 1.3.6 (including) | 1.3.6 (including) |
Xoops | Xoops | 1.3.7 (including) | 1.3.7 (including) |
Xoops | Xoops | 1.3.8 (including) | 1.3.8 (including) |
Xoops | Xoops | 1.3.9 (including) | 1.3.9 (including) |
Xoops | Xoops | 1.3.10 (including) | 1.3.10 (including) |
Xoops | Xoops | 2.0.0 (including) | 2.0.0 (including) |
Xoops | Xoops | 2.0.0_rc1 (including) | 2.0.0_rc1 (including) |
Xoops | Xoops | 2.0.0_rc2 (including) | 2.0.0_rc2 (including) |
Xoops | Xoops | 2.0.0_rc3 (including) | 2.0.0_rc3 (including) |
Xoops | Xoops | 2.0.1 (including) | 2.0.1 (including) |
Xoops | Xoops | 2.0.2 (including) | 2.0.2 (including) |
Xoops | Xoops | 2.0.3 (including) | 2.0.3 (including) |
Xoops | Xoops | 2.0.4 (including) | 2.0.4 (including) |
Xoops | Xoops | 2.0.5.1 (including) | 2.0.5.1 (including) |
Xoops | Xoops | 2.0.5.2 (including) | 2.0.5.2 (including) |
Xoops | Xoops | 2.0.5_rc (including) | 2.0.5_rc (including) |
Xoops | Xoops | 2.0.6 (including) | 2.0.6 (including) |
Xoops | Xoops | 2.0.7 (including) | 2.0.7 (including) |
Xoops | Xoops | 2.0.7.1 (including) | 2.0.7.1 (including) |
Xoops | Xoops | 2.0.7.2 (including) | 2.0.7.2 (including) |
Xoops | Xoops | 2.0.7.3 (including) | 2.0.7.3 (including) |
Xoops | Xoops | 2.0.9 (including) | 2.0.9 (including) |
Xoops | Xoops | 2.0.9.2 (including) | 2.0.9.2 (including) |
Xoops | Xoops | 2.0.9.3 (including) | 2.0.9.3 (including) |
Xoops | Xoops | 2.0.10 (including) | 2.0.10 (including) |
Xoops | Xoops | 2.0.10_rc (including) | 2.0.10_rc (including) |
Xoops | Xoops | 2.0.11 (including) | 2.0.11 (including) |
Xoops | Xoops | 2.0.12 (including) | 2.0.12 (including) |
Xoops | Xoops | 2.0.12a (including) | 2.0.12a (including) |
Xoops | Xoops | 2.0.13 (including) | 2.0.13 (including) |
Xoops | Xoops | 2.0.13.1 (including) | 2.0.13.1 (including) |
Xoops | Xoops | 2.0.13.2 (including) | 2.0.13.2 (including) |
Xoops | Xoops | 2.0.14 (including) | 2.0.14 (including) |
Xoops | Xoops | 2.0.14-rc1 (including) | 2.0.14-rc1 (including) |
Xoops | Xoops | 2.0.15 (including) | 2.0.15 (including) |
Xoops | Xoops | 2.0.16 (including) | 2.0.16 (including) |
Xoops | Xoops | 2.0.17 (including) | 2.0.17 (including) |
Xoops | Xoops | 2.0.17.1 (including) | 2.0.17.1 (including) |
Xoops | Xoops | 2.0.18 (including) | 2.0.18 (including) |
Xoops | Xoops | 2.0.18.1 (including) | 2.0.18.1 (including) |
Xoops | Xoops | 2.3.0 (including) | 2.3.0 (including) |
Xoops | Xoops | 2.3.0_alpha_3 (including) | 2.3.0_alpha_3 (including) |
Xoops | Xoops | 2.3.0_alpha1 (including) | 2.3.0_alpha1 (including) |
Xoops | Xoops | 2.3.0_alpha2 (including) | 2.3.0_alpha2 (including) |
Xoops | Xoops | 2.3.0_beta (including) | 2.3.0_beta (including) |
Xoops | Xoops | 2.3.0_rc (including) | 2.3.0_rc (including) |
Xoops | Xoops | 2.3.0_rc2 (including) | 2.3.0_rc2 (including) |
Xoops | Xoops | 2.3.0_rc3 (including) | 2.3.0_rc3 (including) |
Xoops | Xoops | 2.3.1 (including) | 2.3.1 (including) |
Xoops | Xoops | 2.3.1_rc (including) | 2.3.1_rc (including) |
Xoops | Xoops | 2.3.2a (including) | 2.3.2a (including) |
Xoops | Xoops | 2.3.2b (including) | 2.3.2b (including) |
Xoops | Xoops | 2.3.3 (including) | 2.3.3 (including) |
Xoops | Xoops | 2.4.0_beta_1 (including) | 2.4.0_beta_1 (including) |
Xoops | Xoops | 2.4.0_beta_2 (including) | 2.4.0_beta_2 (including) |
Xoops | Xoops | 2.4.0_rc (including) | 2.4.0_rc (including) |