CVE Database
/

CVE-2006-3939

Back to search

CVE-2006-3939

Published: Jul 31, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

ScriptsCenter ezUpload Pro 2.2.0 allows remote attackers to perform administrative activities without authentication in (1) filter.php, which permits changing the Extensions Mode file type; (2) access.php, which permits changing the Protection Method; (3) edituser.php, which permits adding upload capabilities to user accounts; (4) settings.php, which permits changing the admin information; and (5) index.php, which permits uploading of arbitrary files.

VendorProductVersions

n/a

n/a

affected
n/a

References

19175
vdb-entry
x_refsource_BID
1305
third-party-advisory
x_refsource_SREASON
20060726 EzUpload multi file vulnerabilities
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now