5.1

CVE-2006-3362

Exploit
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GeeklogGeeklog Version1.4.0
GeeklogGeeklog Version1.4.0_sr1
GeeklogGeeklog Version1.4.0_sr2
GeeklogGeeklog Version1.4.0_sr3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.97% 0.911
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://retrogod.altervista.org/toenda_100_shizouka_xpl.html
Exploit
http://secunia.com/advisories/20886
Patch
Vendor Advisory
http://secunia.com/advisories/21117
Vendor Advisory
http://www.geeklog.net/article.php/exploit-for-fckeditor-filemanager
http://www.geeklog.net/article.php/geeklog-1.4.0sr4
http://www.securityfocus.com/archive/1/440423/100/0/threaded
http://www.securityfocus.com/bid/18767
Exploit
http://www.securityfocus.com/bid/19072
Exploit
http://www.securityfocus.com/bid/30950
http://www.vupen.com/english/advisories/2006/2611
http://www.vupen.com/english/advisories/2006/2868
https://exchange.xforce.ibmcloud.com/vulnerabilities/27469
https://exchange.xforce.ibmcloud.com/vulnerabilities/27494
https://exchange.xforce.ibmcloud.com/vulnerabilities/27799
https://www.exploit-db.com/exploits/1964
https://www.exploit-db.com/exploits/2035
https://www.exploit-db.com/exploits/6344