CVE Vulnerabilities

CVE-2006-2931

Published: Jun 21, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by uploading and later directly accessing certain files.

Affected Software

Name Vendor Start Version End Version
Cms_mundo Hotwebscripts 1.0 (including) 1.0 (including)
Cms_mundo Hotwebscripts 1.0_build_007 (including) 1.0_build_007 (including)

References