6.4

CVE-2006-2330

Exploit
PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php Fusion ≫ Php Fusion Version 6.00.3
Php Fusion ≫ Php Fusion Version 6.00.105
Php Fusion ≫ Php Fusion Version 6.00.106
Php Fusion ≫ Php Fusion Version 6.00.107
Php Fusion ≫ Php Fusion Version 6.00.109
Php Fusion ≫ Php Fusion Version 6.00.110
Php Fusion ≫ Php Fusion Version 6.00.204
Php Fusion ≫ Php Fusion Version 6.00.206
Php Fusion ≫ Php Fusion Version 6.00.303
Php Fusion ≫ Php Fusion Version 6.00.304
Php Fusion ≫ Php Fusion Version 6.00.306
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.84% 0.939
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19992
Patch
Vendor Advisory
http://securityreason.com/securityalert/873
http://www.osvdb.org/25537
http://www.php-fusion.co.uk/news.php
Patch
http://www.securityfocus.com/archive/1/433277/100/0/threaded
http://www.securityfocus.com/bid/17898
Exploit
http://www.vupen.com/english/advisories/2006/1735
https://exchange.xforce.ibmcloud.com/vulnerabilities/26388