PT-2006-3295 · Php Fusion · Php-Fusion

Rgod

·

Published

2006-05-12

·

Updated

2018-10-18

·

CVE-2006-2330

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP-Fusion versions 6.00.306 and earlier
Description The issue allows remote authenticated users to upload files of arbitrary types by using a filename that contains two or more extensions, ending in an assumed-valid extension such as .gif. This bypasses the validation, enabling the upload and potential execution of malicious files, for example, an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
Recommendations For PHP-Fusion versions 6.00.306 and earlier, consider restricting file uploads to only explicitly allowed extensions and validate file types based on their content rather than just their extensions. As a temporary workaround, restrict access to the file upload feature until a proper fix is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2330

Affected Products

Php-Fusion