PT-2006-3389 · Dubanner · Dubanner
Dj_Remix_20
·
Published
2006-05-17
·
Updated
2024-01-26
·
CVE-2006-2428
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DUbanner version 3.1
Description
The issue allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, to the
add.asp endpoint, probably due to client-side enforcement that can be bypassed.Recommendations
For version 3.1, consider restricting access to the
add.asp endpoint to prevent arbitrary file uploads until a patch is available. As a temporary workaround, limit the types of file extensions that can be uploaded to prevent potential code execution.Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dubanner