5

CVE-2006-2530

Exploit
avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Snitz CommunicationsAvatar Mod Version1.3
   Snitz CommunicationsSnitz Forums 2000 Version3.4.02
   Snitz CommunicationsSnitz Forums 2000 Version3.4.03
   Snitz CommunicationsSnitz Forums 2000 Version3.4.04
   Snitz CommunicationsSnitz Forums 2000 Version3.4.05
   Snitz CommunicationsSnitz Forums 2000 Version3.4.06
   Snitz CommunicationsSnitz Forums 2000 Version3.4.07
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.65% 0.734
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20148
Patch
Vendor Advisory
http://www.codescan.com/Advisories/CodeScanLabs_AvatarMod.html
Exploit
http://www.security-assessment.com/Whitepapers/0x00_vs_ASP_File_Uploads.pdf
http://www.securityfocus.com/archive/1/434366/100/0/threaded
http://www.securityfocus.com/bid/18014
http://www.vupen.com/english/advisories/2006/1854
https://exchange.xforce.ibmcloud.com/vulnerabilities/26546