CVE-2006-3608
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
- Affected products
- Flatnuke
- Flatnuke
- ≤ 2.5.7, 1.0, 1.5, 1.6, 1.7, 1.8, 2.0, 2.5.1, 2.5.3, 2.5.5, 2.5.6
- Fix
- Available
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 2.2% (81th percentile)
- NVD status
- Modified
- Published
- 2006-07-14
CVE-2006-3608 at NVD
1 known exploit for CVE-2006-3608
Proof-of-concept code and exploit modules indexed by Sploitus