CVE-2007-5188: High severity Xoops Xoops vulnerability
Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5188?
CVE-2007-5188 is considered a critical severity vulnerability due to its potential for remote file uploads.
How do I fix CVE-2007-5188?
To fix CVE-2007-5188, upgrade to a version of XOOPS later than 2.0.17.1-RC1 that addresses this vulnerability.
What types of attacks are possible with CVE-2007-5188?
CVE-2007-5188 allows remote attackers to upload arbitrary files, potentially leading to server compromise.
Which versions of XOOPS are affected by CVE-2007-5188?
CVE-2007-5188 affects XOOPS versions 2.0.17.1-RC1 and earlier.
What components are involved in CVE-2007-5188?
CVE-2007-5188 involves the uploader class in class/uploader.php and class/mimetypes.inc.php.