First published: Sat Apr 09 2005(Updated: )
RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Xm Memberstats | =1.05r3 | |
Runcms | =1.1 | |
Runcms | =1.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1031 is classified as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2005-1031, disable the 'Allow custom avatar upload' feature in your RUNCMS or e-Xoops installation.
CVE-2005-1031 affects RUNCMS versions 1.1 and 1.1A, and possibly other products based on e-Xoops.
CVE-2005-1031 allows remote attackers to upload arbitrary files, potentially leading to remote code execution.
As of now, there is no specific patch for CVE-2005-1031, and the recommended action is to adjust settings to restrict file uploads.