PT-2006-3845 · Cms Mundo · Cms Mundo

Published

2006-06-21

·

Updated

2018-10-18

·

CVE-2006-2931

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CMS Mundo versions prior to 1.0 build 008
Description The issue arises from improper verification of uploaded image files, allowing remote attackers to execute arbitrary PHP code. This can be achieved by uploading and later directly accessing certain files.
Recommendations For CMS Mundo versions prior to 1.0 build 008, update to version 1.0 build 008 or later to resolve the issue. As a temporary workaround, consider restricting access to image upload functionality until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2931

Affected Products

Cms Mundo