4.6

CVE-2006-3608

Exploit
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FlatnukeFlatnuke Version <= 2.5.7
FlatnukeFlatnuke Version1.0
FlatnukeFlatnuke Version1.5
FlatnukeFlatnuke Version1.6
FlatnukeFlatnuke Version1.7
FlatnukeFlatnuke Version1.8
FlatnukeFlatnuke Version2.0
FlatnukeFlatnuke Version2.5.1
FlatnukeFlatnuke Version2.5.3
FlatnukeFlatnuke Version2.5.5
FlatnukeFlatnuke Version2.5.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.22% 0.803
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:N/AC:H/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://retrogod.altervista.org/flatnuke257_adv.html
Exploit
http://secunia.com/advisories/21051
http://securitytracker.com/id?1016499
http://www.securityfocus.com/archive/1/439975/100/0/threaded
http://www.securityfocus.com/archive/1/442421/100/0/threaded
http://www.securityfocus.com/bid/18966
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/27731