7.5
CVSSv2

CVE-2006-3158

Published: 22/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote malicious users to bypass security checks and upload or execute arbitrary php code via the add action.

Vulnerable Product Search on Vulmon Subscribe to Product

eduha meeting eduha meeting

Exploits

source: wwwsecurityfocuscom/bid/18499/info Eduha Meeting is prone to an arbitrary file-upload vulnerability An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process This may facilitate unauthorized access or privilege escalation; other attacks are also possible http ...