A vulnerability has been discovered in the Tutorials module for Xoops and E-Xoops. The problem occurs in the function used by the module to allow the uploading of images to the remote server. It has been discovered that a remote user may be able to upload arbitrary files via this facility. This could allow a malicious script to be uploaded to the server, which could subsequently be executed by making a remote request for the file. Successful exploitation of this vulnerability could potentially allow for the execution of arbitrary system commands with the privileges of the target httpd server.
A vulnerability has been discovered in the Tutorials module for Xoops and E-Xoops. The problem occurs in the function used by the module to allow the uploading of images to the remote server. It has been discovered that a remote user may be able to upload arbitrary files via this facility. This could allow a malicious script to be uploaded to the server, which could subsequently be executed by making a remote request for the file. Successful exploitation of this vulnerability could potentially allow for the execution of arbitrary system commands with the privileges of the target httpd server.