CVE-2006-0169
N/A
N/A
Summary
addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://evuln.com/vulns/23/summary.html
- http://www.securityfocus.com/bid/16208
- http://secunia.com/advisories/18399
- http://www.securityfocus.com/archive/1/421626/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24070
- http://www.vupen.com/english/advisories/2006/0147
References
- http://evuln.com/vulns/23/summary.html
- http://www.securityfocus.com/bid/16208
- http://secunia.com/advisories/18399
- http://www.securityfocus.com/archive/1/421626/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24070
- http://www.vupen.com/english/advisories/2006/0147
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.