CVE-2005-2614 Information
Feb 14, 2021
cve
Description
Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server which allows remote attackers to execute arbitrary commands via a filename containing .php.rar\ or other multiple extensions that include .php.
Reference
http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0440.html http://secunia.com/advisories/16433 http://securitytracker.com/id?1014673 http://www.securityfocus.com/bid/14564
Share on: