PT-2006-2662 · Eric Gerdes · Crafty Syntax Image Gallery

·

CVE-2006-1668

·

Published

2006-04-07

·

Updated

2024-02-14

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Eric Gerdes Crafty Syntax Image Gallery (CSIG) versions 3.1g and earlier
Description: The issue allows remote authenticated users to upload and execute arbitrary PHP code. This can be achieved by sending a multipart/form-data POST request with a .jpg filename in the fullimage parameter and the ext parameter set to .php.
Recommendations: For versions 3.1g and earlier, restrict access to the newimage.php file to prevent unauthorized uploads until a fix is available. As a temporary workaround, consider disabling the execution of PHP code in uploaded files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1668

Affected Products

Crafty Syntax Image Gallery