CVE-2006-3608

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:flatnuke:flatnuke:1.8:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:2.0:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:1.6:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:1.7:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:*:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:1.0:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:1.5:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:2.5.5:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:2.5.6:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:flatnuke:flatnuke:2.5.3:*:*:*:*:*:*:*

Information

Published : 2006-07-18 08:46

Updated : 2018-10-18 09:48


NVD link : CVE-2006-3608

Mitre link : CVE-2006-3608


JSON object : View

Advertisement

dedicated server usa

Products Affected

flatnuke

  • flatnuke