| ID | CVE-2006-3128 | ||||||
| Sažetak | choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:H/Au:S/C:P/I:P/A:P | ||||||
| Zadnje važnije ažuriranje | 18-10-2018 - 16:46 | ||||||
| Objavljeno | 21-06-2006 - 23:02 |

