CVE Database
/

CVE-2006-3070

Back to search

CVE-2006-3070

Published: Jun 19, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-2318
vdb-entry
x_refsource_VUPEN
18465
vdb-entry
x_refsource_BID
20592
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now