Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Xoops/E-Xoops Tutorials Module Remote Command Execution Vulnerability

A vulnerability has been discovered in the Tutorials module for Xoops and E-Xoops. The problem occurs in the function used by the module to allow the uploading of images to the remote server. It has been discovered that a remote user may be able to upload arbitrary files via this facility. This could allow a malicious script to be uploaded to the server, which could subsequently be executed by making a remote request for the file.

Successful exploitation of this vulnerability could potentially allow for the execution of arbitrary system commands with the privileges of the target httpd server.







 

Privacy Statement
Copyright 2009, SecurityFocus