4.6
CVSSv2

CVE-2006-3608

Published: 18/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Gallery module in Simone Vellei Flatnuke 2.5.7 and previous versions, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

Vulnerable Product Search on Vulmon Subscribe to Product

flatnuke flatnuke 1.8

flatnuke flatnuke 2.0

flatnuke flatnuke 1.6

flatnuke flatnuke 1.7

flatnuke flatnuke

flatnuke flatnuke 1.0

flatnuke flatnuke 1.5

flatnuke flatnuke 2.5.5

flatnuke flatnuke 2.5.6

flatnuke flatnuke 2.5.1

flatnuke flatnuke 2.5.3

Exploits

source: wwwsecurityfocuscom/bid/18966/info FlatNuke is prone to a remote file-include vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver ...