PT-2006-5368 · Unknown · The Address Book
Published
2006-12-31
·
Updated
2017-07-20
·
CVE-2006-4581
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
The Address Book version 1.04e
Description
The issue concerns an unrestricted file upload vulnerability. It allows remote attackers to upload arbitrary PHP scripts because the software validates the Content-Type header but not the file extension.
Recommendations
For version 1.04e, consider restricting file uploads to only allow specific, necessary file extensions as a temporary workaround until a patch is available. Additionally, validate both the Content-Type header and the file extension to prevent uploading arbitrary scripts.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Address Book