CVE
- Id
- 11949
- CVE No.
- CVE-2005-0743
- Status
- Candidate
- Description
- The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.
- Phase
- Assigned (20050313)
- Votes
- None (candidate not yet proposed)
- Comments