CVE-2006-3128
CVE-2006-3128
choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://biyosecurity.be/bugs/easycms.txthttp://secunia.com/advisories/20733http://securitytracker.com/id?1016335https://exchange.xforce.ibmcloud.com/vulnerabilities/27281http://www.osvdb.org/26633http://www.securityfocus.com/archive/1/437705/100/0/threadedhttp://www.securityfocus.com/bid/18496http://www.vupen.com/english/advisories/2006/2419