PT-2006-3295 · Php Fusion · Php-Fusion

Rgod

·

Publicado

2006-05-12

·

Atualizado

2018-10-18

·

CVE-2006-2330

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP-Fusion versions 6.00.306 and earlier
Description The issue allows remote authenticated users to upload files of arbitrary types by using a filename that contains two or more extensions, ending in an assumed-valid extension such as .gif. This bypasses the validation, enabling the upload and potential execution of malicious files, for example, an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
Recommendations For PHP-Fusion versions 6.00.306 and earlier, consider restricting file uploads to only explicitly allowed extensions and validate file types based on their content rather than just their extensions. As a temporary workaround, restrict access to the file upload feature until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2330

Produtos afetados

Php-Fusion