CVE-2006-2330

PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php_fusion:php_fusion:6.00.3:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.105:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.106:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.107:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.109:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.110:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.204:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.206:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.303:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.304:*:*:*:*:*:*:*
cpe:2.3:a:php_fusion:php_fusion:6.00.306:*:*:*:*:*:*:*

History

21 Nov 2024, 00:11

Type Values Removed Values Added
References () http://secunia.com/advisories/19992 - Patch, Vendor Advisory () http://secunia.com/advisories/19992 - Patch, Vendor Advisory
References () http://securityreason.com/securityalert/873 - () http://securityreason.com/securityalert/873 -
References () http://www.osvdb.org/25537 - () http://www.osvdb.org/25537 -
References () http://www.php-fusion.co.uk/news.php - Patch () http://www.php-fusion.co.uk/news.php - Patch
References () http://www.securityfocus.com/archive/1/433277/100/0/threaded - () http://www.securityfocus.com/archive/1/433277/100/0/threaded -
References () http://www.securityfocus.com/bid/17898 - Exploit () http://www.securityfocus.com/bid/17898 - Exploit
References () http://www.vupen.com/english/advisories/2006/1735 - () http://www.vupen.com/english/advisories/2006/1735 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26388 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26388 -

Information

Published : 2006-05-12 00:02

Updated : 2025-04-03 01:03


NVD link : CVE-2006-2330

Mitre link : CVE-2006-2330

CVE.ORG link : CVE-2006-2330


JSON object : View

Products Affected

php_fusion

  • php_fusion