CVE Vulnerabilities

CVE-2006-3608

Published: Jul 18, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

Affected Software

Name Vendor Start Version End Version
Flatnuke Flatnuke * 2.5.7 (including)
Flatnuke Flatnuke 1.0 (including) 1.0 (including)
Flatnuke Flatnuke 1.5 (including) 1.5 (including)
Flatnuke Flatnuke 1.6 (including) 1.6 (including)
Flatnuke Flatnuke 1.7 (including) 1.7 (including)
Flatnuke Flatnuke 1.8 (including) 1.8 (including)
Flatnuke Flatnuke 2.0 (including) 2.0 (including)
Flatnuke Flatnuke 2.5.1 (including) 2.5.1 (including)
Flatnuke Flatnuke 2.5.3 (including) 2.5.3 (including)
Flatnuke Flatnuke 2.5.5 (including) 2.5.5 (including)
Flatnuke Flatnuke 2.5.6 (including) 2.5.6 (including)

References