Логотип exploitDog
bind:CVE-2006-3128
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2006-3128

Количество 2

Количество 2

nvd логотип

CVE-2006-3128

больше 19 лет назад

choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.

CVSS2: 4.6
EPSS: Низкий
github логотип

GHSA-2cv5-5qgg-939j

почти 4 года назад

choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-3128

choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.

CVSS2: 4.6
1%
Низкий
больше 19 лет назад
github логотип
GHSA-2cv5-5qgg-939j

choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу