CVE Vulnerabilities

CVE-2006-2319

Published: May 12, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the .asp portion of the filename.

Affected Software

NameVendorStart VersionEnd Version
IdealbbIdeal_science1.5.0_beta1 (including)1.5.0_beta1 (including)
IdealbbIdeal_science1.5.0_beta2 (including)1.5.0_beta2 (including)
IdealbbIdeal_science1.5.0_beta3 (including)1.5.0_beta3 (including)
IdealbbIdeal_science1.5.0_beta4 (including)1.5.0_beta4 (including)
IdealbbIdeal_science1.5.0_rc1 (including)1.5.0_rc1 (including)
IdealbbIdeal_science1.5.1 (including)1.5.1 (including)
IdealbbIdeal_science1.5.2 (including)1.5.2 (including)
IdealbbIdeal_science1.5.2a (including)1.5.2a (including)
IdealbbIdeal_science1.5.2b (including)1.5.2b (including)
IdealbbIdeal_science1.5.2c (including)1.5.2c (including)
IdealbbIdeal_science1.5.3 (including)1.5.3 (including)
IdealbbIdeal_science1.5.3_beta1 (including)1.5.3_beta1 (including)
IdealbbIdeal_science1.5.3_beta2 (including)1.5.3_beta2 (including)
IdealbbIdeal_science1.5.3a (including)1.5.3a (including)
IdealbbIdeal_science1.5.3b (including)1.5.3b (including)
IdealbbIdeal_science1.5.4a (including)1.5.4a (including)

References