CVE-2006-3939 Information
Feb 14, 2021
cve
Description
ScriptsCenter ezUpload Pro 2.2.0 allows remote attackers to perform administrative activities without authentication in (1) filter.php which permits changing the Extensions Mode file type; (2) access.php which permits changing the Protection Method; (3) edituser.php which permits adding upload capabilities to user accounts; (4) settings.php which permits changing the admin information; and (5) index.php which permits uploading of arbitrary files.
Reference
http://securityreason.com/securityalert/1305 http://www.securityfocus.com/archive/1/441172/100/0/threaded http://www.securityfocus.com/bid/19175
Share on: