dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php).
References
Configurations
History
No history.
Information
Published : 2006-12-14 00:28
Updated : 2024-02-04 17:13
NVD link : CVE-2006-6511
Mitre link : CVE-2006-6511
CVE.ORG link : CVE-2006-6511
JSON object : View
Products Affected
dadaimc
- dadaimc
CWE