CVE-2006-3608 Information
Feb 14, 2021
cve
Description
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier when Gallery uploads are enabled does not restrict the extensions of uploaded files that begin with a GIF header which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
Reference
http://retrogod.altervista.org/flatnuke257_adv.html http://secunia.com/advisories/21051 http://securitytracker.com/id?1016499 http://www.securityfocus.com/archive/1/439975/100/0/threaded http://www.securityfocus.com/archive/1/442421/100/0/threaded http://www.securityfocus.com/bid/18966 https://exchange.xforce.ibmcloud.com/vulnerabilities/27731
Share on: