index.php in Eduha Meeting does not properly restrict file extensions...
Vulnerability Description
index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass security checks and upload or execute arbitrary php code via the add action.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3158
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27296
- http://www.vupen.com/english/advisories/2006/2428
- http://www.biyosecurity.be/bugs/meeting.txt
- http://www.securityfocus.com/bid/18499
- http://www.osvdb.org/26627
- http://www.securityfocus.com/archive/1/437992/100/0/threaded
- http://secunia.com/advisories/20731
Affected Vendor
eduha meeting
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.