PT-2006-3284 · Ideal Science · Ideal Bb

Published

2006-05-12

·

Updated

2018-10-18

·

CVE-2006-2319

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ideal Science Ideal BB version 1.5.4a and earlier
Description The issue arises from improper checking of file extensions before upload, allowing remote attackers to upload and execute an ASP script. This can be achieved by including a 0x00 character before the ".asp" portion of the filename, effectively bypassing the file extension check.
Recommendations For Ideal Science Ideal BB version 1.5.4a and earlier, consider restricting file uploads to only necessary and trusted sources, and implement proper validation of file extensions to prevent malicious uploads. As a temporary workaround, consider disabling file upload functionality until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2319

Affected Products

Ideal Bb