Get XOOPS XOOPS FAQ Forums News Themes Modules

XOOPS vs. Herko Coomans

Make a donation

Please select an amount to donate


Do you want your username revealed with your donation?
Yes - List me as a Generous Donor
No - List my donation as from an Anonymous Donor


Search

Local Support Sites

Cumulus Tag Cloud

admin Arabic banner block Christmas comments cumulus DayDawn dhsoft e-Commerce E-Learning Google GUI hacks instant-zero jQuery module news Nordic Olédrion oxygen PageRank security SEO simple-XOOPS sport tag Theme wiki xoops

New Users

Registering user

# 97575

GabrielHan

Welcome to XOOPS!
XOOPS Code hosted on SourceForge
[Main Page]

XOOPS Security

From XOOPS CMS (Content Management System)

Main Page | Recent changes | Edit this page | Page history | Switch to MediaWiki mode

Printable version | Disclaimers | Privacy policy
Category: Core

Posted by phppp on 2007/10/1 4:46:56

XOOPS Uploader Security

Reported: Posted by phppp on 2007/10/1 4:46:56
Here is reported last hack for security details.

There is potential vulnerability identified in uploader class in case upload configuration is not set properly by modules.

The patch is applicable to all XOOPS versions.

Download from SourceForge XOOPS : XOOPS uploader patch 071001 release

Upload the two files /class/uploader.php and /class/mimetypes.inc.php to your /class/ folder and overwrite existent files.

You are highly encouraged to implement the patch to your existent XOOPS system.

Retrieved from "http://www.xoops.org/modules/mediawiki/index.php/XOOPS_Security"

This page has been accessed 6,749 times. This page was last modified 17:29, 11 January 2008. Content is available under XOOPS CMS (Content Management System).