PT-2006-3974 · Zeroboard · Zeroboard

Choi Min-Sung

·

Publicado

2006-06-19

·

Atualizado

2018-10-18

·

CVE-2006-3070

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zeroboard version 4.1 pl8
Description The issue allows remote attackers to bypass restrictions for uploading files with executable extensions. This is achieved by uploading a .htaccess file that includes an AddType directive, which assigns an executable module to files with assumed-safe extensions. For example, an attacker can assign the txt extension to be handled by application/x-httpd-php, effectively making .txt files executable.
Recommendations For Zeroboard version 4.1 pl8, consider disabling the upload of .htaccess files or restricting the use of the AddType directive in .htaccess files to prevent exploitation. Additionally, restrict access to the write ok.php file to minimize the risk of uploading malicious files.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3070

Produtos afetados

Zeroboard