CVE-2006-3676
CVE-2006-3676
admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0434.htmlhttp://secunia.com/advisories/21099http://securityreason.com/securityalert/1268https://exchange.xforce.ibmcloud.com/vulnerabilities/27858http://www.osvdb.org/27417http://www.redteam-pentesting.de/advisories/rt-sa-2006-006.txthttp://www.securityfocus.com/archive/1/440643/100/0/threadedhttp://www.securityfocus.com/bid/19091