CVE Database
/

CVE-2006-2330

Back to search

CVE-2006-2330

Published: May 12, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.

VendorProductVersions

n/a

n/a

affected
n/a

References

873
third-party-advisory
x_refsource_SREASON
25537
vdb-entry
x_refsource_OSVDB
19992
third-party-advisory
x_refsource_SECUNIA
17898
vdb-entry
x_refsource_BID
ADV-2006-1735
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now