Xoops/E-Xoops Tutorials Module Remote Command Execution Vulnerability
BID:7927
Info
Xoops/E-Xoops Tutorials Module Remote Command Execution Vulnerability
| Bugtraq ID: | 7927 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2003 12:00AM |
| Updated: | Jun 16 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to ac3 <[email protected]>. |
| Vulnerable: |
Xoops Xoops Tutorials Module 2.0 |
| Not Vulnerable: |
Xoops Xoops Tutorials Module 2.1 |
Discussion
Xoops/E-Xoops Tutorials Module Remote Command Execution Vulnerability
A vulnerability has been discovered in the Tutorials module for Xoops and E-Xoops. The problem occurs in the function used by the module to allow the uploading of images to the remote server. It has been discovered that a remote user may be able to upload arbitrary files via this facility. This could allow a malicious script to be uploaded to the server, which could subsequently be executed by making a remote request for the file.
Successful exploitation of this vulnerability could potentially allow for the execution of arbitrary system commands with the privileges of the target httpd server.
A vulnerability has been discovered in the Tutorials module for Xoops and E-Xoops. The problem occurs in the function used by the module to allow the uploading of images to the remote server. It has been discovered that a remote user may be able to upload arbitrary files via this facility. This could allow a malicious script to be uploaded to the server, which could subsequently be executed by making a remote request for the file.
Successful exploitation of this vulnerability could potentially allow for the execution of arbitrary system commands with the privileges of the target httpd server.
Solution / Fix
Xoops/E-Xoops Tutorials Module Remote Command Execution Vulnerability
Solution:
The vendor released Tutorials 2.1 to address this issue.
Xoops Xoops Tutorials Module 2.0
Solution:
The vendor released Tutorials 2.1 to address this issue.
Xoops Xoops Tutorials Module 2.0
-
Xoops Xoops Tutorials 2.1
http://www.mytutorials.info/modules/mydownloads/
References
Xoops/E-Xoops Tutorials Module Remote Command Execution Vulnerability
References:
References:
- E-Xoops Home Page (E-Xoops)
- ProManager Homepage (Promanager)
- Xoops Tutorials Module Home Page (www.mytutorials.info)
- Directory traversal vulnerability on Xoops/E-xoops CMS module "tutorials" ("ac3"
)