Sploitus

CVE-2006-3608

1 known exploit for CVE-2006-3608

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

Affected products
Flatnuke
Flatnuke
≤ 2.5.7, 1.0, 1.5, 1.6, 1.7, 1.8, 2.0, 2.5.1, 2.5.3, 2.5.5, 2.5.6
Fix
Available
CVSS 2.0
4.6 MEDIUM
EPSS
2.2% (81th percentile)
NVD status
Modified
Published
2006-07-14
CVE-2006-3608 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-3608

Proof-of-concept code and exploit modules indexed by Sploitus