PT-2006-6972 · Php · Php Upload Center

Gregstar

·

Published

2006-12-07

·

Updated

2017-10-19

·

CVE-2006-6360

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP Upload Center version 2.0
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter in the activate.php file.
Recommendations For PHP Upload Center version 2.0, consider restricting access to the activate.php file or validating the footerpage parameter to prevent remote file inclusion attacks. As a temporary workaround, consider disabling the activate.php file until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6360

Affected Products

Php Upload Center