Xoops
Archived Posts from this Category
Archived Posts from this Category
TITLE:
XOOPS “b_system_comments_show()” Security Bypass
SECUNIA ADVISORY ID:
SA28264
VERIFY ADVISORY:
http://secunia.com/advisories/28264/
CRITICAL:
Not critical
IMPACT:
Security Bypass
WHERE:
From remote
SOFTWARE:
Xoops 2.x
http://secunia.com/product/327/
DESCRIPTION:
A weakness has been reported in XOOPS, which can be exploited by
malicious users to bypass certain security restrictions.
The weakness is caused due to missing permission checks within the
“b_system_comments_show()” function in
htdocs/modules/system/blocks/system_blocks.php. This can be exploited
to read the comments of restricted modules.
The weakness is reported in versions prior to 2.0.18.
SOLUTION:
Update to version 2.0.18.
PROVIDED AND/OR DISCOVERED BY:
Reported by InstantZero.
ORIGINAL ADVISORY:
http://sourceforge.net/tracker/index.php?func=detail&aid=1808484&group_id=41586&atid=430840
0 comments Friday 04 Jan 2008 | Guardian | Xoops
TITLE:
XOOPS Uploader Class Unspecified Vulnerability
SECUNIA ADVISORY ID:
SA27006
VERIFY ADVISORY:
http://secunia.com/advisories/27006/
CRITICAL:
Moderately critical
IMPACT:
System access
WHERE:
From remote
SOFTWARE:
Xoops 2.x
http://secunia.com/product/327/
Xoops 1.3.x
http://secunia.com/product/1357/
DESCRIPTION:
A vulnerability has been reported in XOOPS, which potentially can be
exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an unspecified error within the XOOPS
uploader class when modules have set the upload configuration not
properly. This can potentially be exploited to upload malicious files.
SOLUTION:
Apply patch.
http://downloads.sourceforge.net/xoops/xoops-uploader-patch-071001.zip
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
http://www.xoops.org/modules/news/article.php?storyid=3963
0 comments Wednesday 03 Oct 2007 | Guardian | Xoops