PT-2006-3284 · Ideal Science · Ideal Bb
Published
2006-05-12
·
Updated
2018-10-18
·
CVE-2006-2319
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ideal Science Ideal BB version 1.5.4a and earlier
Description
The issue arises from improper checking of file extensions before upload, allowing remote attackers to upload and execute an ASP script. This can be achieved by including a 0x00 character before the ".asp" portion of the filename, effectively bypassing the file extension check.
Recommendations
For Ideal Science Ideal BB version 1.5.4a and earlier, consider restricting file uploads to only necessary and trusted sources, and implement proper validation of file extensions to prevent malicious uploads. As a temporary workaround, consider disabling file upload functionality until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ideal Bb