CVE-2006-6556

The eyeHome function in apps/eyeHome.eyeapp/aplic.php in EyeOS before 0.9.3-3 allows remote attackers to upload and execute arbitrary code via dangerous file extensions that are not all lowercase, which bypasses a cleansing operation.
Configurations

Configuration 1 (hide)

cpe:2.3:o:eyeos:eyeos:0.9.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:22

Type Values Removed Values Added
References () http://eyeos.blogspot.com/2006/12/eyeos-093-4-released-webmail-eyeapp.html - Patch () http://eyeos.blogspot.com/2006/12/eyeos-093-4-released-webmail-eyeapp.html - Patch
References () http://prdownloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?download - Patch () http://prdownloads.sourceforge.net/eyeos/eyeOS-0.9.3-4.tar.gz?download - Patch
References () http://secunia.com/advisories/23388 - () http://secunia.com/advisories/23388 -
References () http://www.securityfocus.com/bid/21639 - () http://www.securityfocus.com/bid/21639 -
References () http://www.vupen.com/english/advisories/2006/4962 - () http://www.vupen.com/english/advisories/2006/4962 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/30844 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/30844 -

Information

Published : 2006-12-14 18:28

Updated : 2024-11-21 00:22


NVD link : CVE-2006-6556

Mitre link : CVE-2006-6556

CVE.ORG link : CVE-2006-6556


JSON object : View

Products Affected

eyeos

  • eyeos