PT-2006-3284 · Ideal Science · Ideal Bb
Publicado
2006-05-12
·
Atualizado
2018-10-18
·
CVE-2006-2319
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ideal Science Ideal BB version 1.5.4a and earlier
Description
The issue arises from improper checking of file extensions before upload, allowing remote attackers to upload and execute an ASP script. This can be achieved by including a 0x00 character before the ".asp" portion of the filename, effectively bypassing the file extension check.
Recommendations
For Ideal Science Ideal BB version 1.5.4a and earlier, consider restricting file uploads to only necessary and trusted sources, and implement proper validation of file extensions to prevent malicious uploads. As a temporary workaround, consider disabling file upload functionality until a proper fix is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ideal Bb