CVE-2006-6511
N/A
N/A
Summary
dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://secunia.com/advisories/23305
- http://www.vupen.com/english/advisories/2006/4977
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30862
- http://bugs.dadaimc.org/view.php?id=191
References
- http://secunia.com/advisories/23305
- http://www.vupen.com/english/advisories/2006/4977
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30862
- http://bugs.dadaimc.org/view.php?id=191
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.