PoC Index

CVE-2006-3608

MEDIUM 4.6EPSS 2.3%

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

CVSS v2.0
4.6 MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
EPSS
2.26% chance of exploitation in the next 30 days, 82th percentile
Published
2006-07-14
Updated
2024-08-07

ExploitDB entries (1)

References

Related