7.5
CVE-2006-7070
- EPSS 3.9%
- Veröffentlicht 02.03.2007 21:18:00
- Zuletzt bearbeitet 16.06.2026 22:34:19
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then calling the rename function.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.9% | 0.889 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://retrogod.altervista.org/etomite_061_cmd.html
http://secunia.com/advisories/21208
http://securityreason.com/securityalert/2326
http://securitytracker.com/id?1016593
http://www.etomite.org/forums/index.php?showtopic=5757&st=0&p=35605&#entry35605
http://www.osvdb.org/27543
http://www.securityfocus.com/archive/1/441202/100/0/threaded
http://www.securityfocus.com/bid/19157
https://exchange.xforce.ibmcloud.com/vulnerabilities/27947
https://www.exploit-db.com/exploits/2072