Lucene search

K
prionPRIOn knowledge basePRION:CVE-2006-2330
HistoryMay 12, 2006 - 12:02 a.m.

Input validation

2006-05-1200:02:00
PRIOn knowledge base
www.prio-n.com
5

7.2 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.9%

PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in “.php.gif” and contains PHP code in EXIF metadata.

7.2 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.9%

Related for PRION:CVE-2006-2330