PT-2006-3389 · Dubanner · Dubanner

Dj_Remix_20

·

Publicado

2006-05-17

·

Atualizado

2024-01-26

·

CVE-2006-2428

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DUbanner version 3.1
Description The issue allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, to the add.asp endpoint, probably due to client-side enforcement that can be bypassed.
Recommendations For version 3.1, consider restricting access to the add.asp endpoint to prevent arbitrary file uploads until a patch is available. As a temporary workaround, limit the types of file extensions that can be uploaded to prevent potential code execution.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-2428

Produtos afetados

Dubanner