Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-3070

Опубликовано: 19 июн. 2006
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zeroboard:zeroboard:4.1_pl8:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01954
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restrictions for uploading files with executable extensions by uploading a .htaccess file that with an AddType directive that assigns an executable module to files with assumed-safe extensions, as demonstrated by assigning the txt extension to be handled by application/x-httpd-php.

EPSS

Процентиль: 83%
0.01954
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other