>> Xoops Uploader Class PHP4 Extension Arbitrary File Upload Vulnerability
Title : Xoops Uploader Class PHP4 Extension Arbitrary File Upload Vulnerability VUPEN ID : VUPEN/ADV-2007-3315 CVE ID : CVE-2007-5188
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-10-01
Technical Description
A vulnerability has been identified in Xoops, which could be exploited by remote attackers to bypass security restrictions and compromise a vulnerable web server. This issue is caused by an error in the Uploader class when processing a file with a PHP4 file extension, which could be exploited by malicious users to upload malicious PHP scripts and execute arbitrary commands with the privileges of the web server.