First published: Wed Oct 03 2007(Updated: )
Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Xm Memberstats | <=2.0.17.1-rc1 | |
Xoops | <=2.0.17.1-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5188 is considered a critical severity vulnerability due to its potential for remote file uploads.
To fix CVE-2007-5188, upgrade to a version of XOOPS later than 2.0.17.1-RC1 that addresses this vulnerability.
CVE-2007-5188 allows remote attackers to upload arbitrary files, potentially leading to server compromise.
CVE-2007-5188 affects XOOPS versions 2.0.17.1-RC1 and earlier.
CVE-2007-5188 involves the uploader class in class/uploader.php and class/mimetypes.inc.php.