Security Advisory

CVE-2006-3608

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-07-14 21:00:00
Last updated 2024-08-07 18:39:52
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.