CVE-2006-3362

Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.4.0_sr1:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.4.0_sr2:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.4.0_sr3:*:*:*:*:*:*:*
cpe:2.3:a:toenda_software_development:toendacms:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:toenda_software_development:toendacms:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:toenda_software_development:toendacms:0.7:*:*:*:*:*:*:*
cpe:2.3:a:toenda_software_development:toendacms:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-07-06 20:05

Updated : 2024-02-04 16:52


NVD link : CVE-2006-3362

Mitre link : CVE-2006-3362

CVE.ORG link : CVE-2006-3362


JSON object : View

Products Affected

toenda_software_development

  • toendacms

geeklog

  • geeklog