Lucene search

K
cveMitreCVE-2006-2530
HistoryMay 22, 2006 - 11:10 p.m.

CVE-2006-2530

2006-05-2223:10:00
CWE-264
mitre
web.nvd.nist.gov
30
cve-2006-2530
snitz forums 3.4
remote attackers
file upload vulnerability
null byte
codescan product

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.033

Percentile

91.5%

avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.

Affected configurations

Nvd
Node
snitz_communicationsavatar_modMatch1.3
AND
snitz_communicationssnitz_forums_2000Match3.4.02
OR
snitz_communicationssnitz_forums_2000Match3.4.03
OR
snitz_communicationssnitz_forums_2000Match3.4.04
OR
snitz_communicationssnitz_forums_2000Match3.4.05
OR
snitz_communicationssnitz_forums_2000Match3.4.06
OR
snitz_communicationssnitz_forums_2000Match3.4.07
VendorProductVersionCPE
snitz_communicationsavatar_mod1.3cpe:2.3:a:snitz_communications:avatar_mod:1.3:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.02cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.02:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.03cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.03:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.04cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.04:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.05cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.05:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.06cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.06:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.07cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.07:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.033

Percentile

91.5%

Related for CVE-2006-2530