Back to search
CVE-2006-0936
Published: Feb 28, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://nsag.ru/vuln/894.html
x_refsource_MISC
19014
third-party-advisory
x_refsource_SECUNIA
16823
vdb-entry
x_refsource_BID
20060225 NSA Group Security Advisory NSAG-¹202-25.02.2006 Vulnerability WEBSITE GENERATOR 3.3
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now