PT-2006-2662 · Eric Gerdes · Crafty Syntax Image Gallery

Undefined1

·

Published

2006-04-07

·

Updated

2024-02-14

·

CVE-2006-1668

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Eric Gerdes Crafty Syntax Image Gallery (CSIG) versions 3.1g and earlier
Description: The issue allows remote authenticated users to upload and execute arbitrary PHP code. This can be achieved by sending a multipart/form-data POST request with a .jpg filename in the fullimage parameter and the ext parameter set to .php.
Recommendations: For versions 3.1g and earlier, restrict access to the newimage.php file to prevent unauthorized uploads until a fix is available. As a temporary workaround, consider disabling the execution of PHP code in uploaded files to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2006-1668

Affected Products

Crafty Syntax Image Gallery