PT-2006-2662 · Eric Gerdes · Crafty Syntax Image Gallery
Undefined1
·
Published
2006-04-07
·
Updated
2024-02-14
·
CVE-2006-1668
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Eric Gerdes Crafty Syntax Image Gallery (CSIG) versions 3.1g and earlier
Description:
The issue allows remote authenticated users to upload and execute arbitrary PHP code. This can be achieved by sending a multipart/form-data POST request with a .jpg filename in the
fullimage parameter and the ext parameter set to .php.Recommendations:
For versions 3.1g and earlier, restrict access to the
newimage.php file to prevent unauthorized uploads until a fix is available. As a temporary workaround, consider disabling the execution of PHP code in uploaded files to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crafty Syntax Image Gallery