PT-2006-3389 · Dubanner · Dubanner

Dj_Remix_20

·

Published

2006-05-17

·

Updated

2024-01-26

·

CVE-2006-2428

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DUbanner version 3.1
Description The issue allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, to the add.asp endpoint, probably due to client-side enforcement that can be bypassed.
Recommendations For version 3.1, consider restricting access to the add.asp endpoint to prevent arbitrary file uploads until a patch is available. As a temporary workaround, limit the types of file extensions that can be uploaded to prevent potential code execution.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2006-2428

Affected Products

Dubanner