Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xoops XOOPS uploader class 'uploader.php'和'mimetypes.inc.php'未明文件上传漏洞
Vulnerability Description
Xoops 2.0.17.1-RC1版本及其早期版本中的XOOPS uploader class存在未明漏洞,远程攻击者上载任意文件可以借助未明向量,与class/uploader.php和class/mimetypes.inc.php中设置的不正确的上载配置有关,可能是一个省略.php4扩展名的不完全的黑名单。
CVSS Information
N/A
Vulnerability Type
N/A