CVE-2006-3608
MEDIUM 4.6EPSS 2.3%
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
- CVSS v2.0
- 4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P - EPSS
- 2.26% chance of exploitation in the next 30 days, 82th percentile
- Published
- 2006-07-14
- Updated
- 2024-08-07