choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not...
Vulnerability Description
choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3128
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/20733
- http://www.securityfocus.com/archive/1/437705/100/0/threaded
- http://securitytracker.com/id?1016335
- http://www.vupen.com/english/advisories/2006/2419
- http://biyosecurity.be/bugs/easycms.txt
- http://www.securityfocus.com/bid/18496
- http://www.osvdb.org/26633
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27281
Affected Vendor
easy-cms
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.