CVE-2006-0695
N/A
N/A
Summary
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24684
- http://www.vupen.com/english/advisories/2006/0536
- http://sourceforge.net/project/shownotes.php?release_id=392826
- http://www.securityfocus.com/bid/16603
- http://secunia.com/advisories/18810
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24684
- http://www.vupen.com/english/advisories/2006/0536
- http://sourceforge.net/project/shownotes.php?release_id=392826
- http://www.securityfocus.com/bid/16603
- http://secunia.com/advisories/18810
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.