PT-2006-3845 · Cms Mundo · Cms Mundo
Published
2006-06-21
·
Updated
2018-10-18
·
CVE-2006-2931
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CMS Mundo versions prior to 1.0 build 008
Description
The issue arises from improper verification of uploaded image files, allowing remote attackers to execute arbitrary PHP code. This can be achieved by uploading and later directly accessing certain files.
Recommendations
For CMS Mundo versions prior to 1.0 build 008, update to version 1.0 build 008 or later to resolve the issue. As a temporary workaround, consider restricting access to image upload functionality until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cms Mundo