CVE-2006-6879
MEDIUM 6.0EPSS 1.9%
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter.
- CVSS v2.0
- 6.0 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P - EPSS
- 1.88% chance of exploitation in the next 30 days, 78th percentile
- Published
- 2007-01-05
- Updated
- 2024-08-07