CVE-2005-0743: High severity Xoops Xoops vulnerability
Published Mar 13, 2005
·Updated
The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.
Affected Software
17 affected components
Xoops Xoops=1.0_rc1
Xoops Xoops=1.0_rc3
Xoops Xoops=1.0_rc3.0.5
Xoops Xoops=1.3.5
Xoops Xoops=1.3.6
Xoops Xoops=1.3.7
Xoops Xoops=1.3.8
Xoops Xoops=1.3.9
Xoops Xoops=1.3.10
Xoops Xoops=2.0
Xoops Xoops=2.0.1
Xoops Xoops=2.0.2
Xoops Xoops=2.0.3
Xoops Xoops=2.0.5
Xoops Xoops=2.0.5.1
Xoops Xoops=2.0.5.2
Xoops Xoops=2.0.9.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0743?
CVE-2005-0743 is considered a critical vulnerability due to its ability to allow remote code execution through file uploads.
2
How do I fix CVE-2005-0743?
To fix CVE-2005-0743, upgrade to XOOPS version 2.0.10 or later which addresses the vulnerability.
3
What systems are affected by CVE-2005-0743?
CVE-2005-0743 affects XOOPS versions 2.0.9.2 and earlier, as well as several 1.x versions.
4
What type of attack does CVE-2005-0743 enable?
CVE-2005-0743 enables remote attackers to upload arbitrary PHP scripts, leading to potential server compromise.
5
Is there a workaround for CVE-2005-0743 if I cannot upgrade?
If unable to upgrade, consider disabling the avatar upload feature or implementing stricter file type validation.