7.5

CVE-2005-0743

The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.

Data is provided by the National Vulnerability Database (NVD)
XoopsXoops Version1.0_rc1
XoopsXoops Version1.0_rc3
XoopsXoops Version1.0_rc3.0.5
XoopsXoops Version1.3.5
XoopsXoops Version1.3.6
XoopsXoops Version1.3.7
XoopsXoops Version1.3.8
XoopsXoops Version1.3.9
XoopsXoops Version1.3.10
XoopsXoops Version2.0
XoopsXoops Version2.0.1
XoopsXoops Version2.0.2
XoopsXoops Version2.0.3
XoopsXoops Version2.0.5
XoopsXoops Version2.0.5.1
XoopsXoops Version2.0.5.2
XoopsXoops Version2.0.9.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.91% 0.737
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P